CVE-2022-46487

HIGH

SCONE <5.8.0 - Memory Corruption

Title source: llm
STIX 2.1

Description

Improper initialization of x87 and SSE floating-point configuration registers in the __scone_entry component of SCONE before 5.8.0 for Intel SGX allows a local attacker to compromise the execution integrity of floating-point operations in an enclave or access sensitive information via side-channel analysis.

Scores

CVSS v3 7.8
EPSS 0.0017
EPSS Percentile 37.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-665
Status published
Products (1)
scontain/scone < 5.8.0
Published Dec 30, 2023
Tracked Since Feb 18, 2026