Improper access control in keylime - CVE-2022-23948

 

Improper access control in keylime - CVE-2022-23948

Published: January 27, 2022 / Updated: May 7, 2026


Vulnerability identifier: #VU130488
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23948
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper access control in the secure mount check logic in the Keylime agent when checking for a secure mount. A local user can create a previously mounted unprivileged mount to disclose sensitive information.

The issue can allow secrets to be leaked to other processes on the host.


Affected software

keylime
Fedora
keylime

How to mitigate CVE-2022-23948

Install security update from vendor's website.

keylime - update to 6.3.0
keylime - addressed in versions 6.3.0-2.fc34, 6.3.0-2.fc35

External References

Related Security Bulletins