Vulnerability Description
A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Keylime | Keylime | - |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux Eus | 9.2 |
| Redhat | Enterprise Linux For Ibm Z Systems | 9.0_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 9.2_s390x |
| Redhat | Enterprise Linux For Power Little Endian | 9.0_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian Eus | 9.0_ppc64le |
| Redhat | Enterprise Linux Server Aus | 9.2 |
| Fedoraproject | Fedora | 38 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2023:5080Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-38200Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2222692Issue TrackingThird Party Advisory
- https://github.com/keylime/keylime/pull/1421Patch
- https://access.redhat.com/errata/RHSA-2023:5080Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-38200Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2222692Issue TrackingThird Party Advisory
- https://github.com/keylime/keylime/pull/1421Patch
- https://lists.fedoraproject.org/archives/list/[email protected]
FAQ
What is CVE-2023-38200?
CVE-2023-38200 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all avail...
How severe is CVE-2023-38200?
CVE-2023-38200 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38200?
Check the references section above for vendor advisories and patch information. Affected products include: Keylime Keylime, Redhat Enterprise Linux, Redhat Enterprise Linux Eus, Redhat Enterprise Linux For Ibm Z Systems, Redhat Enterprise Linux For Ibm Z Systems Eus.