Medium severity5.5NVD Advisory· Published Dec 30, 2023· Updated Jun 17, 2026
CVE-2023-38021
CVE-2023-38021
Description
An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.32 for Intel SGX. Lack of pointer-alignment validation logic in entry functions allows a local attacker to access unauthorized information. This relates to the enclave_ecall function and system call layer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:fortanix:confidential_computing_manager:*:*:*:*:*:intel_software_guard_extensions:*:*Range: <3.32
- Fortanix EnclaveOS/Confidential Computing Manager (CCM) Platform for Intel SGXdescription
- Range: <3.32
Patches
Vulnerability mechanics
References
5- github.com/openenclave/openenclave/security/advisories/GHSA-v3vm-9h66-wm76nvdNot ApplicableThird Party Advisory
- jovanbulck.github.io/files/oakland24-pandora.pdfnvdThird Party Advisory
- www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/advisory-guidance/stale-data-read-from-xapic.htmlnvdNot ApplicableThird Party Advisory
- www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/processor-mmio-stale-data-vulnerabilities.htmlnvdNot ApplicableThird Party Advisory
- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00657.htmlnvdNot ApplicableThird Party Advisory
News mentions
0No linked articles in our index yet.