{"id":"CVE-2021-44421","details":"The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information via side-channel analysis.","modified":"2026-07-09T05:45:52.970653Z","published":"2022-03-10T17:44:15.447Z","references":[{"type":"ADVISORY","url":"https://github.com/occlum/occlum/compare/0.25.0...v0.26.0"},{"type":"FIX","url":"https://github.com/occlum/occlum/commit/36918e42bf6732c4d3996bc99eb013eb6b90b249"},{"type":"EVIDENCE","url":"https://github.com/occlum/occlum/blob/821ea843ae21037e6cff5268306d2da1fb131552/src/libos/src/util/mem_util.rs#L130"},{"type":"EVIDENCE","url":"https://github.com/occlum/occlum/blob/821ea843ae21037e6cff5268306d2da1fb131552/src/libos/src/util/mem_util.rs#L51"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/occlum/occlum","events":[{"introduced":"0"},{"fixed":"a428ea3409bab6d605042552594c41d716d02ab8"},{"fixed":"36918e42bf6732c4d3996bc99eb013eb6b90b249"}],"database_specific":{"cpe":"cpe:2.3:a:occlum_project:occlum:*:*:*:*:*:software_guard_extensions:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.26.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.25.0","0.24.2","0.24.1","0.24.0","0.23.7","0.23.6","0.23.5","0.23.4","0.23.3","0.23.2","0.23.1","0.23.0","0.22.0","0.21.0","0.20.0","0.18.1","0.17.0","0.16.0","0.15.1","0.15.0","0.14.0","0.13.1","0.13.0","0.12.2","0.12.1","0.12.0","0.11.0","0.10.0","0.9.0","0.8.0","0.7.0","0.6.0","0.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-44421.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}