CVE-2021-3406
Summary
| CVE | CVE-2021-3406 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-25 20:15:00 UTC |
| Updated | 2023-11-07 03:37:00 UTC |
| Description | A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1932469 – (CVE-2021-3406) CVE-2021-3406 keylime: Key cryptographic chain of trust breakage |
MISC |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| Key cryptographic chain of trust breakage · Advisory · keylime/keylime · GitHub |
MISC |
github.com |
Third Party Advisory |
| [SECURITY] Fedora 34 Update: keylime-6.0.0-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: keylime-6.0.0-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 281595 Fedora Security Update for keylime (FEDORA-2021-b7854ccfe4)