Severity
7.8HIGH
EPSS
0.0%
top 95.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15
Latest updateMay 24

Description

An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sections of the Enclave memory address. We recommend updating your library.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:NExploitability: 1.0 | Impact: 4.2

Affected Packages2 packages

NVDgoogle/asylo0.6.0
CVEListV5google_llc/asylounspecified0.6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6g37-4jmq-qq2x: An arbitrary memory overwrite vulnerability in Asylo versions up to 02022-05-24
CVEList
CVE-2020-8935: An arbitrary memory overwrite vulnerability in Asylo versions up to 02020-12-15
CVE-2020-8935 (HIGH CVSS 7.8) | An arbitrary memory overwrite vulne | cvebase.io