Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information via side-channel analysis.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Occlum 安全漏洞
Vulnerability Description
Occlum是一个适用于英特尔 SGX 的内存安全、多进程库操作系统。 Occlum for Intel SGX 0.26.0 之前版本中 util/mem_util.rs 存在安全漏洞,该漏洞源于指针验证逻辑充当混淆代理。允许本地攻击者通过边信道分析访问未经授权的信息。
CVSS Information
N/A
Vulnerability Type
N/A