Skip to content

Registrar vulnerable to Denial-of-service attack via a single open connection

Moderate
maugustosilva published GHSA-pg75-v6fp-8q59 Aug 1, 2023

Package

Keylime

Affected versions

<7.3.0

Patched versions

7.4.0

Description

Impact

Keylime registrar is prone to a simple denial of service attack in which an adversary opens a connection to the TLS port (by default, port 8891) blocking further, legitimate connections. As long as the connection is open, the registrar is blocked and cannot serve any further clients (agents and tenants), which prevents normal operation. The problem does not affect the verifier.

Patches

Users should upgrade to release 7.4.0

Credit

Reported by: Florian Kohnhäuser/@flozilla
Patched-by: Florian Kohnhäuser/@flozilla

Severity

Moderate

CVE ID

CVE-2023-38200

Weaknesses

No CWEs