First published: Wed Feb 24 2021(Updated: )
A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/keylime | <6.0.0 | 6.0.0 |
Keylime Keylime | <=5.8.1 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3406 is a vulnerability found in Keylime 5.8.1 and older versions that invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.
The severity of CVE-2021-3406 is critical with a severity value of 9.8.
Keylime versions up to and including 5.8.1 are affected, as well as Fedora version 34.
To fix CVE-2021-3406, update Keylime to version 6.0.0.
You can find more information about CVE-2021-3406 at the following references: - Red Hat Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1932469 - GitHub Security Advisory: https://github.com/keylime/keylime/security/advisories/GHSA-78f8-6c68-375m - Fedora Package Announcement: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YAWKEF2LVXUME266T6RNRVBGAD375QAT/