PT-2022-5285 · Keylime+4 · Keylime+4
Sergio Correia
·
Published
2022-10-27
·
Updated
2025-04-29
·
CVE-2022-3500
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
keylime versions prior to 6.5.1
Description
The issue is related to improperly handled exceptions in keylime, which can be exploited to create errors on the verifier, stopping attestation attempts and leaving a host in an attested state without verification. This creates a false sense of security for keylime users, as they may conclude that a node or agent is correctly attested when attestations are not taking place. The vulnerability can be triggered by transient network failure conditions, such as recoverable device driver crashes.
Recommendations
For versions prior to 6.5.1, apply the patch available at https://github.com/keylime/keylime/pull/1128/files to fix the issue. Only running verifiers need to be patched, and after applying the patch, the keylime verifier needs to be restarted.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Red Hat
Rocky Linux
Suse
Keylime