Headline
CVE-2022-23950: Keylime: Revocation Notifier's UNIX unprivileged domain socket which can allow DOS
In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.
Impact
Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.
Patches
Users should upgrade to at least 6.3.x.
Workarounds
None
Credit
Many thanks to Matthias Gerstner for finding this issue and for Alberto Planas for the fix.
For more information
If you have any questions or comments about this advisory:
- Email us at [email protected]
- Ask on #keylime channel on the CNCF Slack