Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-22548— Arbitrary enclave memory overread vulnerability in Asylo TrustedPrimitives::UntrustedCall

CVSS 6.5 · Medium EPSS 0.02% · P5
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-22548

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Arbitrary enclave memory overread vulnerability in Asylo TrustedPrimitives::UntrustedCall
Source: NVD (National Vulnerability Database)
Vulnerability Description
An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted memory to trusted memory, if the latter is later copied out, it allows for reading of memory regions from the trusted region. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
在缓冲区结束位置之后访问内存
Source: NVD (National Vulnerability Database)
Vulnerability Title
Google Asylo 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Google Asylo是美国谷歌(Google)公司的一个用于开发可信应用程序的框架。该软件支持创建一个可信任的执行环境,包括软件隔离和硬件隔离。 asylo存在安全漏洞,该漏洞源于攻击者可利用该漏洞可以将指向不可信内存的指针指向可信内存区域,这将导致将可信内存复制到可信内存,如果之后将可信内存复制出来,则允许从可信区域读取内存区域。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Google LLCAsylo unspecified ~ 0.6.2 -

II. Public POCs for CVE-2021-22548

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-22548

登录查看更多情报信息。

Same Patch Batch · Google LLC · 2021-06-08 · 3 CVEs total

CVE-2021-225496.5 MEDIUMArbitrary enclave memory overwrite vulnerability in Asylo TrustedPrimitives::UntrustedCall
CVE-2021-225506.5 MEDIUMEnclave memory overwrite/overread vulnerability in Asylo UntrustedCacheMalloc::GetBuffer

IV. Related Vulnerabilities

V. Comments for CVE-2021-22548

No comments yet


Leave a comment