First published: Wed Sep 21 2022(Updated: )
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Keylime Keylime | <6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-23950.
The severity of CVE-2022-23950 is high, with a severity value of 7.5.
CVE-2022-23950 affects the Keylime software version up to (but excluding) 6.3.0.
CVE-2022-23950 allows unprivileged users to prohibit keylime operations by exploiting a fixed /tmp path for UNIX domain socket.
To fix CVE-2022-23950, update Keylime software to version 6.3.0 or later.