Authentication Bypass by Spoofing in keylime - CVE-2021-43310
Published: January 27, 2022 / Updated: May 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to reset or replay encryption keys and payload data.
The vulnerability exists due to authentication bypass by spoofing in the Keylime agent when handling crafted key reset or replay requests. A remote attacker can send a specially crafted request or replay captured U and V keys and payload data to reset or replay encryption keys and payload data.
Depending on how the client is configured, new revocation and attestation actions may be added, which could lead to remote code execution.
Affected software
Fedora
keylime
How to mitigate CVE-2021-43310
keylime - addressed in versions 6.3.0-2.fc34, 6.3.0-2.fc35