Keylime是Keylime开源的一个利用 TPM 技术的开源可扩展信任系统。 Keylime存在安全漏洞,该漏洞源于验证器使用硬编码的挑战随机数进行TPM引用证明而非加密随机值,可能导致攻击者囤积有效TPM引用并重放以逃避检测。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| None | None | 7.14.0< 7.14.2 |
affected |
| Red Hat | Red Hat Enterprise Linux 10 | 0:7.14.1-5.el10_2.1< * |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | - | 7.14.0 ~ 7.14.2 | - |
|
| Red Hat | Red Hat Enterprise Linux 10 | 0:7.14.1-5.el10_2.1 ~ * |
cpe:/o:redhat:enterprise_linux:10.2
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet