Insufficient Control Flow Management in Intel SGX SDK for Linux
CVE-2022-26841
2.5LOW
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 16 February 2023
What is CVE-2022-26841?
The Intel SGX SDK for Linux prior to version 2.16.100.1 exhibits insufficient control flow management, which may permit an authenticated user to potentially disclose sensitive information through local access. This flaw could lead to unauthorized exposure of data which should remain confidential, emphasizing the importance of updating to the latest version to mitigate such risks. For further details, please visit Intel's advisory.
Affected Version(s)
Intel(R) SGX SDK software for Linux before version 2.16.100.1