CVE-2023-38200Uncontrolled Resource Consumption in Keylime

Severity
7.5HIGHNVD
EPSS
0.7%
top 27.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24
Latest updateAug 1

Description

A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

PyPIkeylime/keylime< 7.4.0

Also affects: Fedora 38, Enterprise Linux 9.0, 9.2

Patches

🔴Vulnerability Details

3
GHSA
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection2023-08-01
OSV
Keylime's registrar vulnerable to Denial-of-service attack via a single open connection2023-08-01
CVEList
Keylime: registrar is subject to a dos against ssl connections2023-07-24

📋Vendor Advisories

1
Red Hat
keylime: registrar is subject to a DoS against SSL connections2023-07-12