First published: Wed Feb 05 2025(Updated: )
A flaw was found in Keylime. Due to added strict type checking, Keylime fails to read data from a database populated by a previous version of Keylime. This flaw allows an attacker to make the service unavailable by populating the database before an update to the affected version. Affected component: Keylime Affected version of Keylime: 7.12.0
Affected Software | Affected Version | How to fix |
---|---|---|
Keylime (Keylime) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2343894 is considered critical due to the potential for denial of service.
To fix REDHAT-BUG-2343894, update Keylime to the latest version that addresses the strict type checking issue.
REDHAT-BUG-2343894 affects the Keylime service that relies on database interactions.
REDHAT-BUG-2343894 can facilitate a denial of service attack by populating the database before an update.
There are no known workarounds for REDHAT-BUG-2343894 other than applying the necessary updates.