CVE-2022-23948

A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled by previously created unprivileged mounts allowing secrets to be leaked to other processes on the host.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
keylimekeylime
𝑥
< 6.3.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
keylime
bionic
dne
focal
dne
jammy
dne
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
keylime-agent
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-config
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-firewalld
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-logrotate
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-registrar
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-tpm_cert_store
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
keylime-verifier
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed
python3-keylime
suse enterprise desktop 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise desktop 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise desktop 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise desktop 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise sap 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP4
6.3.0-150400.2.5
fixed
suse enterprise server 15 SP5
6.3.2-150400.4.14.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.4.20.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.4.20.1
fixed