Privasys Go 是 Go 编程语言的一个持续维护分支,它为 crypto/tls 模块增加了 RA-TLS(Remote Attestation TLS)支持。在版本 privasys-v0.5.1-go1.26.5 之前,challenge-mode 下的 RA-TLS 证书将远程证明(quote)中的 ReportData 绑定到证书的公钥和客户端随机数(nonce),但未绑定到当前的 TLS 会话。攻击者若获取了 enclave(可信执行环境)的 TLS 私钥,便可将一份真实的远程证明(quote)中
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108265 | 9.1 CRITICAL | enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session |
| CVE-2026-108266 | 9.1 CRITICAL | Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS s |
| CVE-2026-108269 | 9.1 CRITICAL | ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session |
| CVE-2026-108268 | 9.1 CRITICAL | enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session |
No comments yet