Database/Firmware, BMC & network fabric
Intel SGX Platform Software for Linux (AESM daemon): A local attacker can disable the AESM daemon
CVE-2018-3689Firmware, BMC & network fabriccurated
Impact
A local attacker can disable the AESM daemon, which is the component that services remote attestation. Kill it and enclaves on that node can no longer prove what they are - so attestation-gated workloads stop being admitted.
Who can reach it
Local attacker on the node, no special privilege required.
What to do
Upgrade SGX PSW for Linux to 2.1.102 or later, and monitor AESM liveness as a first-class signal on confidential-compute nodes. Userspace daemon update and restart.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.