Keylime's registrar vulnerable to Denial-of-service attack via a single open connection
Description
Published to the GitHub Advisory Database
Aug 1, 2023
Reviewed
Aug 1, 2023
Last updated
Sep 4, 2023
Impact
Keylime
registrar
is prone to a simple denial of service attack in which an adversary opens a connection to the TLS port (by default, port8891
) blocking further, legitimate connections. As long as the connection is open, theregistrar
is blocked and cannot serve any further clients (agents
andtenants
), which prevents normal operation. The problem does not affect theverifier
.Patches
Users should upgrade to release 7.4.0
References