CVE-2022-1053: Input Validation

Published Mar 17, 2022
·
Updated

Hello Team, please check the below report: --------

Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote.

This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM.

Affects all versions of Keylime <6.4.0

Thanks

Other sources

Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM. A successful attack breaks the entire chain of trust because a not validated AK is used by the verifier. This issue is worse if the validation happens first and then the agent gets added to the verifier because the timing is easier and the verifier does not validate the regcount entry being equal to 1,

MITRE

Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM. A successful attack breaks the entire chain of trust because a not validated AK is used by the verifier. This issue is worse if the validation happens first and then the agent gets added to the verifier because the timing is easier and the verifier does not validate the regcount entry being equal to 1. At this time, there are no known workaround.

GitHub

Affected Software

6 affected componentsFixes available
pip/keylime<6.4.0
6.4.0
redhat/keylime<6.4.0
6.4.0
Keylime Keylime<6.4.0
fedoraproject fedora=34
fedoraproject fedora=35
fedoraproject fedora=36

Event History

Mar 17, 2022
Data Sourced
via Red Hat·06:57 AM
DescriptionSeverityAffected Software
May 5, 2022
Advisory Published
03:59 PM
May 6, 2022
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-1053?

CVE-2022-1053 is a vulnerability in Keylime that allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK.

2

How severe is CVE-2022-1053?

CVE-2022-1053 has a severity score of 9.1, making it critical.

3

Which software versions are affected by CVE-2022-1053?

CVE-2022-1053 affects Keylime versions up to but excluding 6.4.0, Fedora versions 34, 35, and 36.

4

How can I fix CVE-2022-1053?

To fix CVE-2022-1053, update to Keylime version 6.4.0 or higher.

5

Where can I find more information about CVE-2022-1053?

More information about CVE-2022-1053 can be found at the following references: [GitHub Advisory](https://github.com/keylime/keylime/security/advisories/GHSA-jf66-3q76-h5p5), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-1053), [GitHub Commit](https://github.com/keylime/keylime/commit/bd5de712acdd77860e7dc58969181e16c7a8dc5d).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203