Back

MEDIUM

Unchecked buffer overrun in ecall_restore

Published Dec 15, 2020

Description

An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to ecall_restore using the attribute output which fails to check the range of a pointer. An attacker can use this pointer to write to arbitrary memory addresses including those within the secure enclave We recommend upgrading past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a

Affected products

Remediation

Vendor solution

We recommend upgrading past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Dec 15, 2020
Updated Aug 4, 2024
Reserved Feb 12, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a