CVE-2023-3674
published 2023-07-19CVE-2023-3674: A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate…
PriorityP48low2.8CVSS 3.1
AVLACLPRLUIRSUCNILAN
EPSS
0.21%
11.5th percentile
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| keylime | keylime | < 7.2.5 | 7.2.5 |
| keylime | keylime | >= 0 < 7.2.5 | 7.2.5 |
| keylime | keylime | >= 0 < 95ce3d86bd2c53009108ffda2dcf553312d733db | 95ce3d86bd2c53009108ffda2dcf553312d733db |
CVSS provenance
nvdv3.12.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
keylime fails to flag device as untrusted when signature does not validate
osv·2023-07-19
CVE-2023-3674 [MEDIUM] keylime fails to flag device as untrusted when signature does not validate
keylime fails to flag device as untrusted when signature does not validate
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
OSV
CVE-2023-3674: A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not
osv·2023-07-19
CVE-2023-3674 CVE-2023-3674: A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
GHSA
keylime fails to flag device as untrusted when signature does not validate
ghsa·2023-07-19
CVE-2023-3674 [MEDIUM] CWE-1283 keylime fails to flag device as untrusted when signature does not validate
keylime fails to flag device as untrusted when signature does not validate
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
Red Hat
kernel: jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
vendor_redhat·2025-10-04·CVSS 7.8
CVE-2023-53616 [HIGH] CWE-1341 kernel: jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
kernel: jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
In the Linux kernel, the following vulnerability has been resolved:
jfs: fix invalid free of JFS_IP(ipimap)->i_imap in diUnmount
syzbot found an invalid-free in diUnmount:
BUG: KASAN: double-free in slab_free mm/slub.c:3661 [inline]
BUG: KASAN: double-free in __kmem_cache_free+0x71/0x110 mm/slub.c:3674
Free of addr ffff88806f410000 by task syz-executor131/3632
CPU: 0 PID: 3632 Comm: syz-executor131 Not tainted 6.1.0-rc7-syzkaller-00012-gca57f02295f1 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022
Call Trace:
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x1b1/0x28e lib/dump_stack.c:106
print_address_description+0x74/0x340 mm/kasan/report.c:284
print_report+0x107/0x
Red Hat
keylime: Attestation failure when the quote's signature does not validate
vendor_redhat·2023-07-12·CVSS 2.3
CVE-2023-3674 [LOW] CWE-1283 keylime: Attestation failure when the quote's signature does not validate
keylime: Attestation failure when the quote's signature does not validate
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:1139https://access.redhat.com/security/cve/CVE-2023-3674https://bugzilla.redhat.com/show_bug.cgi?id=2222903https://github.com/keylime/keylime/commit/95ce3d86bd2c53009108ffda2dcf553312d733dbhttps://access.redhat.com/errata/RHSA-2024:1139https://access.redhat.com/security/cve/CVE-2023-3674https://bugzilla.redhat.com/show_bug.cgi?id=2222903https://github.com/keylime/keylime/commit/95ce3d86bd2c53009108ffda2dcf553312d733db
2023-07-19
Published