SB2022012793 - Fedora 34 update for keylime
Published: January 27, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Authentication Bypass by Spoofing (CVE-ID: CVE-2021-43310)
CWE-ID: CWE-290 - Authentication Bypass by Spoofing
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to reset or replay encryption keys and payload data.
The vulnerability exists due to authentication bypass by spoofing in the Keylime agent when handling crafted key reset or replay requests. A remote attacker can send a specially crafted request or replay captured U and V keys and payload data to reset or replay encryption keys and payload data.
Depending on how the client is configured, new revocation and attestation actions may be added, which could lead to remote code execution.
2) Improper access control (CVE-ID: CVE-2022-23948)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in the secure mount check logic in the Keylime agent when checking for a secure mount. A local user can create a previously mounted unprivileged mount to disclose sensitive information.
The issue can allow secrets to be leaked to other processes on the host.
3) Improper Output Neutralization for Logs (CVE-ID: CVE-2022-23949)
CWE-ID: CWE-117 - Improper Output Neutralization for Logs
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof log entries.
The vulnerability exists due to improper neutralization of special elements used in a log in verifier and registrar logging when processing agent-supplied UUIDs. A remote attacker can supply a crafted UUID to spoof log entries.
The issue can be triggered by a rogue agent.
4) Improper access control (CVE-ID: CVE-2022-23950)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access control in the revocation notifier UNIX domain socket when using a fixed /tmp socket path. A local user can create or interfere with the socket path to cause a denial of service.
5) Improper handling of highly compressed data (CVE-ID: CVE-2022-23951)
CWE-ID: CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of compressed data in quote responses when processing possibly untrusted ZIP data from the agent. A remote attacker can provide a crafted quote response containing zip bomb data to cause a denial of service.
6) Incorrect permission assignment for critical resource (CVE-ID: CVE-2022-23952)
CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in keylime.conf when the file is installed with world-readable permissions. A local user can read the configuration file to disclose sensitive information.
Remediation
Install update from vendor's website.