Improper access control in keylime - CVE-2022-23948
Published: January 27, 2022 / Updated: May 7, 2026
keylime
Detailed vulnerability description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in the secure mount check logic in the Keylime agent when checking for a secure mount. A local user can create a previously mounted unprivileged mount to disclose sensitive information.
The issue can allow secrets to be leaked to other processes on the host.