A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1932469 | issue tracking third party advisory |
https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m | third party advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/ | vendor advisory |