CVE-2021-3406: Critical severity Keylime Keylime vulnerability
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/keylimeto a version that resolves this vulnerability.Fixed in 6.0.0
Event History
Frequently Asked Questions
What is CVE-2021-3406?
CVE-2021-3406 is a vulnerability found in Keylime 5.8.1 and older versions that invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
What is the severity of CVE-2021-3406?
The severity of CVE-2021-3406 is critical with a severity value of 9.8.
What software versions are affected by CVE-2021-3406?
Keylime versions up to and including 5.8.1 are affected, as well as Fedora version 34.
How can I fix CVE-2021-3406?
To fix CVE-2021-3406, update Keylime to version 6.0.0.
Where can I find more information about CVE-2021-3406?
You can find more information about CVE-2021-3406 at the following references: - Red Hat Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1932469 - GitHub Security Advisory: https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m - Fedora Package Announcement: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/