PT-2022-5285 · Keylime+4 · Keylime+4

Sergio Correia

·

Published

2022-10-27

·

Updated

2025-04-29

·

CVE-2022-3500

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions keylime versions prior to 6.5.1
Description The issue is related to improperly handled exceptions in keylime, which can be exploited to create errors on the verifier, stopping attestation attempts and leaving a host in an attested state without verification. This creates a false sense of security for keylime users, as they may conclude that a node or agent is correctly attested when attestations are not taking place. The vulnerability can be triggered by transient network failure conditions, such as recoverable device driver crashes.
Recommendations For versions prior to 6.5.1, apply the patch available at https://github.com/keylime/keylime/pull/1128/files to fix the issue. Only running verifiers need to be patched, and after applying the patch, the keylime verifier needs to be restarted.

Fix

Weakness Enumeration

Related Identifiers

ALSA-2022:8444
BDU:2022-06569
CVE-2022-3500
GHSA-HFF2-X2J9-GXGV
OPENSUSE-SU-2022_4204-1
PYSEC-2022-42995
RHSA-2022:8444
RHSA-2022_8444
RLSA-2022:8444
SUSE-SU-2022:4204-1
SUSE-SU-2022_4204-1

Affected Products

Almalinux
Red Hat
Rocky Linux
Suse
Keylime