CVE-2021-22548

MEDIUM

Asylo <0.6.2 - Memory Corruption

Title source: llm
STIX 2.1

Description

An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted memory to trusted memory, if the latter is later copied out, it allows for reading of memory regions from the trusted region. It is recommended to update past 0.6.2 or git commit https://github.com/google/asylo/commit/53ed5d8fd8118ced1466e509606dd2f473707a5c

Scores

CVSS v3 6.5
EPSS 0.0002
EPSS Percentile 5.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

Details

CWE
CWE-788
Status published
Products (1)
google/asylo < 0.6.2
Published Jun 08, 2021
Tracked Since Feb 18, 2026