Keylime是Keylime开源的一个利用 TPM 技术的开源可扩展信任系统。 Keylime存在安全漏洞,该漏洞源于攻击者可注册新代理并覆盖合法代理身份,可能导致绕过安全控制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Keylime Project | keylime | < 7.14.0 |
affected |
| Red Hat | Red Hat Enterprise Linux 10 | 0:7.12.1-11.el10_1.3< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:7.12.1-2.el10_0.4< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | 0:7.12.1-11.el9_7.3< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:6.5.2-6.el9_2.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:7.3.0-13.el9_4.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:7.3.0-15.el9_6.1< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Keylime Project | keylime | 0 ~ 7.14.0 | - |
|
| Red Hat | Red Hat Enterprise Linux 10 | 0:7.12.1-11.el10_1.3 ~ * |
cpe:/o:redhat:enterprise_linux:10.1
|
|
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:7.12.1-2.el10_0.4 ~ * |
cpe:/o:redhat:enterprise_linux_eus:10.0
|
|
| Red Hat | Red Hat Enterprise Linux 9 | 0:7.12.1-11.el9_7.3 ~ * |
cpe:/a:redhat:enterprise_linux:9::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | 0:6.5.2-6.el9_2.1 ~ * |
cpe:/a:redhat:rhel_e4s:9.2::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:7.3.0-13.el9_4.1 ~ * |
cpe:/a:redhat:rhel_eus:9.4::appstream
|
|
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:7.3.0-15.el9_6.1 ~ * |
cpe:/a:redhat:rhel_eus:9.6::appstream
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet