Information disclosure in Intel SGX SDK for Windows and Intel SGX SDK for Linux - CVE-2020-0551
Published: March 10, 2020
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
Affected software
Intel SGX SDK for Linux
Xen
openEuler
binutils
binutils-debuginfo
binutils-debugsource
binutils-help
binutils-devel
How to mitigate CVE-2020-0551
Install updates from vendor's website.
The list of affected processor families is available here:
https://software.intel.com/security-software-guidance/processors-affected-transient-execution-attack-mitigation-product-cpu-model
binutils - update to 2.34-9
binutils-debuginfo - update to 2.34-9
binutils-debugsource - update to 2.34-9
binutils-help - update to 2.34-9
binutils-devel - update to 2.34-9