PT-2023-26333 · Keylime+3 · Keylime+3

Flozilla

·

Published

2023-07-24

·

Updated

2024-09-16

·

CVE-2023-38200

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Keylime versions prior to 7.4.0
Description A flaw was found in Keylime due to its blocking nature, making the Keylime registrar subject to a remote denial of service against its SSL connections. This allows an attacker to exhaust all available connections, preventing normal operation. The issue affects the registrar component, blocking further legitimate connections, but does not affect the verifier. The problem can be exploited by opening a connection to the TLS port, by default port 8891, which blocks the registrar and prevents it from serving clients, including agents and tenants.
Recommendations For versions prior to 7.4.0, users should upgrade to release 7.4.0 to resolve the issue. As a temporary workaround, consider restricting access to the TLS port, by default port 8891, to minimize the risk of exploitation. Additionally, users can consider disabling the registrar component until the upgrade is applied.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:5080
CVE-2023-38200
GHSA-9GJG-834P-5GVV
GHSA-PG75-V6FP-8Q59
OPENSUSE-SU-2023_3245-1
OPENSUSE-SU-2024:13096-1
RHSA-2023:5080
RHSA-2023_5080
SUSE-SU-2023:3245-1
SUSE-SU-2023_3245-1

Affected Products

Almalinux
Keylime
Red Hat
Suse