Database/Firmware, BMC & network fabric
Intel SGX protected memory subsystem: Insufficient access control in the SGX protected-memory subsystem allows
CVE-2019-0117Firmware, BMC & network fabriccurated
Impact
Insufficient access control in the SGX protected-memory subsystem allows information disclosure from enclave memory to a privileged local user. Part of the long tail of SGX hardware issues that each force a TCB recovery.
Who can reach it
Privileged local access on the host.
What to do
Microcode/platform firmware update and re-attestation of all enclaves. Where the fix ships in microcode it can be late-loaded at boot; where it ships in the platform BIOS, expect an OEM release and a per-node drain and reboot.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.