CVE-2022-1053: Input Validation
Hello Team, please check the below report: --------
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote.
This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM.
Affects all versions of Keylime <6.4.0
Thanks
Other sources
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM. A successful attack breaks the entire chain of trust because a not validated AK is used by the verifier. This issue is worse if the validation happens first and then the agent gets added to the verifier because the timing is easier and the verifier does not validate the regcount entry being equal to 1,
— MITRE
Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM. A successful attack breaks the entire chain of trust because a not validated AK is used by the verifier. This issue is worse if the validation happens first and then the agent gets added to the verifier because the timing is easier and the verifier does not validate the regcount entry being equal to 1. At this time, there are no known workaround.
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-1053?
CVE-2022-1053 is a vulnerability in Keylime that allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK.
How severe is CVE-2022-1053?
CVE-2022-1053 has a severity score of 9.1, making it critical.
Which software versions are affected by CVE-2022-1053?
CVE-2022-1053 affects Keylime versions up to but excluding 6.4.0, Fedora versions 34, 35, and 36.
How can I fix CVE-2022-1053?
To fix CVE-2022-1053, update to Keylime version 6.4.0 or higher.
Where can I find more information about CVE-2022-1053?
More information about CVE-2022-1053 can be found at the following references: [GitHub Advisory](https://github.com/keylime/keylime/security/advisories/GHSA-jf66-3q76-h5p5), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-1053), [GitHub Commit](https://github.com/keylime/keylime/commit/bd5de712acdd77860e7dc58969181e16c7a8dc5d).