Occlum is a lightweight operating system designed to run legacy applications within Intel SGX enclaves, presenting a narrow product scope focused on trusted-execution-environment functionality. The observed vulnerability profile centers on the core Occlum runtime and reflects weakness classes related to observable discrepancies in enclave state or behavior that can undermine isolation guarantees. Current CVE counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Occlum Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44421MEDIUM The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that allows a local attacker to access unauthorized information via | Mar 10, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Occlum Project.
Media articles that mention a CVE ID that affects a product developed by Occlum Project — matched by CVE ID, not by vendor name.