CVE-2021-3406

Source
https://cve.org/CVERecord?id=CVE-2021-3406
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3406.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-3406
Related
  • GHSA-78f8-6c68-375m
Published
2021-02-25T20:15:11.707Z
Modified
2026-02-01T20:16:22.231768Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.

References

Affected packages

Git / github.com/keylime/keylime

Affected ranges

Type
GIT
Repo
https://github.com/keylime/keylime
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

5.*
5.0.0
5.1.0
5.2.0
5.3.0
5.3.1
5.4.0
5.4.1
5.5.0
5.6.0
5.6.1
5.6.2
5.7.0
5.7.1
5.7.2
5.7.3
5.8.0
5.8.1
v2.*
v2.0
v2.1
v2.1.1
v2.2
v2.3
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v3.*
v3.0.0
v3.1.0
v3.1.1
v4.*
v4.0.0
v4.0.1
v5.*
v5.8.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3406.json"