CVE-2022-46487: High severity scone vulnerability
Improper initialization of x87 and SSE floating-point configuration registers in the sconeentry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-point operations in an enclave or access sensitive information via side-channel analysis.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-46487?
CVE-2022-46487 has a high severity rating as it can lead to compromised execution integrity of floating-point operations.
How do I fix CVE-2022-46487?
To fix CVE-2022-46487, upgrade to SCONE version 5.8.0 or later.
Who is affected by CVE-2022-46487?
CVE-2022-46487 affects local users of SCONE versions prior to 5.8.0 in Intel SGX environments.
What types of attacks can be executed using CVE-2022-46487?
CVE-2022-46487 can enable local attackers to compromise the execution integrity and access sensitive information via side-channel attacks.
What component of SCONE is involved in CVE-2022-46487?
CVE-2022-46487 involves improper initialization in the __scone_entry component of SCONE.