REDHAT-BUG-2343894: Medium severity keylime (keylime) vulnerability
A flaw was found in Keylime. Due to added strict type checking, Keylime fails to read data from a database populated by a previous version of Keylime. This flaw allows an attacker to make the service unavailable by populating the database before an update to the affected version. Affected component: Keylime Affected version of Keylime: 7.12.0
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2343894?
The severity of REDHAT-BUG-2343894 is considered critical due to the potential for denial of service.
How do I fix REDHAT-BUG-2343894?
To fix REDHAT-BUG-2343894, update Keylime to the latest version that addresses the strict type checking issue.
What is affected by REDHAT-BUG-2343894?
REDHAT-BUG-2343894 affects the Keylime service that relies on database interactions.
What kind of attack can REDHAT-BUG-2343894 facilitate?
REDHAT-BUG-2343894 can facilitate a denial of service attack by populating the database before an update.
Is there a workaround for REDHAT-BUG-2343894?
There are no known workarounds for REDHAT-BUG-2343894 other than applying the necessary updates.