Skip to content

Keylime: Revocation Notifier's UNIX unprivileged domain socket which can allow DOS

High
mpeters published GHSA-9r9r-f8xc-m875 Jan 27, 2022

Package

keylime (Keylime)

Affected versions

<6.2.0

Patched versions

6.3.0

Description

Impact

Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.

Patches

Users should upgrade to at least 6.3.x.

Workarounds

None

Credit

Many thanks to Matthias Gerstner for finding this issue and for Alberto Planas for the fix.

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2022-23950

Weaknesses

No CWEs

Credits