Enclave OS Mini 是基于 Rust 的运行时环境,用于在 Intel SGX 飞地(enclave)中运行机密应用。在 wasm-v0.40.0 版本之前,SGX 运行时的远程认证(RA-TLS)挑战证书路径将证书的公钥哈希和客户端非ces数(nonce)放入 Quote 的 ReportData 字段中,但遗漏了与当前 TLS 会话绑定的特定值。攻击者若能获取飞地的 TLS 私钥,便可将有效的 Quote 中继到另一个连接上,导致依赖方(relying party)错误地将由攻击者终止的连接识别为经
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Privasys | enclave-os-mini | < wasm-v0.40.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108266 | 9.1 CRITICAL | Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS s |
| CVE-2026-108269 | 9.1 CRITICAL | ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session |
| CVE-2026-108267 | 9.1 CRITICAL | Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS sessi |
| CVE-2026-108268 | 9.1 CRITICAL | enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session |
No comments yet