A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0. Specifically, older versions store agent registration data as bytes, whereas the updated registrar expects str. This issue leads to an exception when processing agent registration requests, causing the agent to fail.
History

Mon, 17 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 15 Mar 2025 09:00:00 +0000

Type Values Removed Values Added
Title keylime: Keylime Registrar DoS Due to Incompatible Database Entry Handling Keylime: keylime registrar dos due to incompatible database entry handling
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Fri, 14 Feb 2025 02:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0. Specifically, older versions store agent registration data as bytes, whereas the updated registrar expects str. This issue leads to an exception when processing agent registration requests, causing the agent to fail.
Title keylime: Keylime Registrar DoS Due to Incompatible Database Entry Handling
Weaknesses CWE-704
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-03-17T17:01:26.257Z

Reserved: 2025-02-05T09:57:50.746Z

Link: CVE-2025-1057

cve-icon Vulnrichment

Updated: 2025-03-17T17:01:17.753Z

cve-icon NVD

Status : Received

Published: 2025-03-15T09:15:10.770

Modified: 2025-03-15T09:15:10.770

Link: CVE-2025-1057

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-02-05T00:00:00Z

Links: CVE-2025-1057 - Bugzilla