CVE-2022-2447
published 2022-09-01CVE-2022-2447: A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from…
PriorityP433medium6.6CVSS 3.1
AVNACHPRHUINSUCHIHAH
EPSS
0.61%
45.0th percentile
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-keystonemiddleware | < python-keystonemiddleware 10.1.0-4 (bookworm) | python-keystonemiddleware 10.1.0-4 (bookworm) |
| openstack | keystone | >= 0 < 2:21.0.1-0ubuntu2.1 | 2:21.0.1-0ubuntu2.1 |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | quay | — | — |
| redhat | storage | — | — |
CVSS provenance
nvdv3.16.6MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
osv7.4HIGH
vendor_ubuntu7.4HIGH
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenStack Keystone vulnerabilities
vendor_ubuntu·2025-12-11·CVSS 7.4
CVE-2022-2447 [HIGH] OpenStack Keystone vulnerabilities
Title: OpenStack Keystone vulnerabilities
Summary: Several security issues were fixed in OpenStack Keystone.
Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens
and s3tokens APIs. A remote attacker could possibly use this issue to
obtain unauthorized access and escalate privileges. (CVE-2025-65073)
It was discovered that OpenStack Keystone only validated the first 72
bytes of an application secret. An attacker could possibly use this issue
to bypass password complexity. (CVE-2021-3563)
It was discovered that OpenStack Keystone had a time lag before a token
should be revoked by the security policy. A remote administrator could use
this issue to maintain access for longer than expected. (CVE-2022-2447)
Instructions: In general, a standard system update will make all
Red Hat
kernel: netlink: Bounds-check struct nlmsgerr creation
vendor_redhat·2025-05-01·CVSS 5.5
CVE-2022-49766 [MEDIUM] kernel: netlink: Bounds-check struct nlmsgerr creation
kernel: netlink: Bounds-check struct nlmsgerr creation
In the Linux kernel, the following vulnerability has been resolved:
netlink: Bounds-check struct nlmsgerr creation
In preparation for FORTIFY_SOURCE doing bounds-check on memcpy(),
switch from __nlmsg_put to nlmsg_put(), and explain the bounds check
for dealing with the memcpy() across a composite flexible array struct.
Avoids this future run-time warning:
memcpy: detected field-spanning write (size 32) of single field "&errmsg->msg" at net/netlink/af_netlink.c:2447 (size 16)
Statement: This patch introduces bounds-checking when creating struct nlmsgerr messages by replacing __nlmsg_put() and memcpy() with nlmsg_put() and unsafe_memcpy(). This prevents potential overreads.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Red Hat
Openstack: Application credential token remains valid longer than expected
vendor_redhat·2022-07-08·CVSS 6.6
CVE-2022-2447 [MEDIUM] CWE-324 Openstack: Application credential token remains valid longer than expected
Openstack: Application credential token remains valid longer than expected
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
Package: fence-agents (Red Hat Enterprise Linux 9) - Not affected
Package: Openstack (Red Hat Integration Camel K 1) - Not affected
Package: Openstack (Red
Debian
CVE-2022-2447: python-keystonemiddleware - A flaw was found in Keystone. There is a time lag (up to one hour in a default c...
vendor_debian·2022·CVSS 6.6
CVE-2022-2447 [MEDIUM] CVE-2022-2447: python-keystonemiddleware - A flaw was found in Keystone. There is a time lag (up to one hour in a default c...
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
Scope: local
bookworm: resolved (fixed in 10.1.0-4)
bullseye: open
forky: resolved (fixed in 10.1.0-4)
sid: resolved (fixed in 10.1.0-4)
trixie: resolved (fixed in 10.1.0-4)
OSV
keystone vulnerabilities
osv·2025-12-11·CVSS 7.4
CVE-2025-65073 [HIGH] keystone vulnerabilities
keystone vulnerabilities
Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens
and s3tokens APIs. A remote attacker could possibly use this issue to
obtain unauthorized access and escalate privileges. (CVE-2025-65073)
It was discovered that OpenStack Keystone only validated the first 72
bytes of an application secret. An attacker could possibly use this issue
to bypass password complexity. (CVE-2021-3563)
It was discovered that OpenStack Keystone had a time lag before a token
should be revoked by the security policy. A remote administrator could use
this issue to maintain access for longer than expected. (CVE-2022-2447)
GHSA
GHSA-r88f-774m-5rj4: A flaw was found in OpenStack
ghsa_unreviewed·2022-09-02
CVE-2022-2447 [HIGH] CWE-672 GHSA-r88f-774m-5rj4: A flaw was found in OpenStack
A flaw was found in OpenStack. The application credential tokens can be used even after they have expired. This flaw allows an authenticated remote attacker to obtain access despite the defender's efforts to remove access.
OSV
CVE-2022-2447: A flaw was found in Keystone
osv·2022-09-01·CVSS 6.6
CVE-2022-2447 [MEDIUM] CVE-2022-2447: A flaw was found in Keystone
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2022-50253 kernel: Linux kernel: Denial of Service in network packet redirection
bugzilla·2025-09-15·CVSS 5.5
CVE-2022-50253 [MEDIUM] CVE-2022-50253 kernel: Linux kernel: Denial of Service in network packet redirection
CVE-2022-50253 kernel: Linux kernel: Denial of Service in network packet redirection
In the Linux kernel, the following vulnerability has been resolved:
bpf: make sure skb->len != 0 when redirecting to a tunneling device
syzkaller managed to trigger another case where skb->len == 0
when we enter __dev_queue_xmit:
WARNING: CPU: 0 PID: 2470 at include/linux/skbuff.h:2576 skb_assert_len include/linux/skbuff.h:2576 [inline]
WARNING: CPU: 0 PID: 2470 at include/linux/skbuff.h:2576 __dev_queue_xmit+0x2069/0x35e0 net/core/dev.c:4295
Call Trace:
dev_queue_xmit+0x17/0x20 net/core/dev.c:4406
__bpf_tx_skb net/core/filter.c:2115 [inline]
__bpf_redirect_no_mac net/core/filter.c:2140 [inline]
__bpf_redirect+0x5fb/0xda0 net/core/filter.c:2163
____bpf_clone_redirect net/core/filter.c:2447 [inline]
bp
Bugzilla
CVE-2022-49766 kernel: netlink: Bounds-check struct nlmsgerr creation
bugzilla·2025-05-01·CVSS 5.5
CVE-2022-49766 [MEDIUM] CVE-2022-49766 kernel: netlink: Bounds-check struct nlmsgerr creation
CVE-2022-49766 kernel: netlink: Bounds-check struct nlmsgerr creation
In the Linux kernel, the following vulnerability has been resolved:
netlink: Bounds-check struct nlmsgerr creation
In preparation for FORTIFY_SOURCE doing bounds-check on memcpy(),
switch from __nlmsg_put to nlmsg_put(), and explain the bounds check
for dealing with the memcpy() across a composite flexible array struct.
Avoids this future run-time warning:
memcpy: detected field-spanning write (size 32) of single field "&errmsg->msg" at net/netlink/af_netlink.c:2447 (size 16)
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025050114-CVE-2022-49766-7b16@gregkh/T
Bugzilla
CVE-2022-2447 Openstack: Application credential token remains valid longer than expected
bugzilla·2022-07-08·CVSS 6.6
CVE-2022-2447 [MEDIUM] CVE-2022-2447 Openstack: Application credential token remains valid longer than expected
CVE-2022-2447 Openstack: Application credential token remains valid longer than expected
Description of problem:
Keystone issues tokens with the default lifespan regardless of the lifespan of the application credentials used to issue them.
If the configured lifespan of an identity token is set to be 1h, and the application credentials expire in 1 minute from now, a newly issued token will outlive the application credentials used to issue it by 59 minutes.
How reproducible: 100%
Steps to Reproduce:
1. Create application credentials with short expiration time (e.g. 10 seconds)
2. openstack token issue
--> the returned token has standard expiration, for example 1 hour. The script below confirms that the token continue being valid after the application credentials expired.
```bash
#!/usr/b
2022-09-01
Published