Enclave OS Virtual 通过在机密虚拟机中运行容器工作负载,并实现端到端远程证明(attestation)来保障安全性。在 tdx-v0.2.43 和 tdx-gpu-v0.6.27 版本之前,TDX/GPU 远程证明 TLS(RA-TLS)证书颁发机构将证书公钥哈希值和客户端随机数(nonce)放置在 Quote 的 ReportData 字段中,但遗漏了与当前活跃 TLS 会话绑定的绑定值。攻击者若获取了机密容器(enclave)的 TLS 私钥,便可将有效的 Quote 中继到另一个连接上,导致
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Privasys | enclave-os-virtual | < tdx-v0.2.43 |
affected |
< tdx-gpu-v0.6.27 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Privasys | enclave-os-virtual | < tdx-v0.2.43 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108265 | 9.1 CRITICAL | enclave-os-mini: RA-TLS challenge certificates were not bound to the TLS session |
| CVE-2026-108266 | 9.1 CRITICAL | Privasys rustls fork: RA-TLS challenge mode did not bind attestation evidence to the TLS s |
| CVE-2026-108269 | 9.1 CRITICAL | ra-tls-clients: RA-TLS challenge verifier accepted quotes not bound to the TLS session |
| CVE-2026-108267 | 9.1 CRITICAL | Privasys Go fork: RA-TLS challenge mode did not bind attestation evidence to the TLS sessi |
No comments yet