CVE-2023-38021: Fortanix Confidential Computing Manager
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.32 for Intel SGX. Lack of pointer-alignment validation logic in entry functions allows a local attacker to access unauthorized information. This relates to the enclave_ecall function and system call layer.
Affected products
- Fortanix Confidential Computing Manager: before 3.32 (fixed in 3.32)
Published 2023-12-30. Last modified 2026-06-17.