CVE-2020-8936: Google Asylo
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to UntrustedCall. UntrustedCall failed to validate the buffer range within sgx_params and allowed the host to return a pointer that was an address within the enclave memory. This allowed an attacker to read memory values from within the enclave.
Affected products
- Google Asylo: up to and including 0.6.0
Published 2020-12-15. Last modified 2026-06-17.