CVE-2023-38021: Fortanix Confidential Computing Manager

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.32 for Intel SGX. Lack of pointer-alignment validation logic in entry functions allows a local attacker to access unauthorized information. This relates to the enclave_ecall function and system call layer.

Affected products

  • Fortanix Confidential Computing Manager: before 3.32 (fixed in 3.32)

Published 2023-12-30. Last modified 2026-06-17.