<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 21:14:53 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-1057 — Keylime: keylime registrar dos due to incompatible database entry handling</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-1057</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; keylime, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9&lt;/p&gt;
&lt;p&gt;A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0. Specifically, older versions store agent registration data as bytes, whereas the updated registrar expects str. This issue leads to an exception when processing agent registration requests, causing the agent to fail.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; keylime, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9&lt;/p&gt;
&lt;p&gt;A flaw was found in Keylime, a remote attestation solution, where strict type checking introduced in version 7.12.0 prevents the registrar from reading database entries created by previous versions, for example, 7.11.0. Specifically, older versions store agent registration data as bytes, whereas the updated registrar expects str. This issue leads to an exception when processing agent registration requests, causing the agent to fail.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-1057</guid>
    </item>
    <item>
      <title>GHSA-9jxq-5x44-gx23 — Keylime registrar is vulnerable to Denial-of-Service attack when updated to version 7.12.0</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9jxq-5x44-gx23</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: keylime&lt;/p&gt;
&lt;p&gt;### Impact
The Keylime `registrar` implemented more strict type checking on version 7.12.0. As a result, when updated to version 7.12.0, the `registrar` will not accept the format of the data previously stored in the database by versions  &amp;gt;= 7.8.0, raising an exception.&lt;/p&gt;
&lt;p&gt;This makes the Keylime `registrar` vulnerable to a Denial-of-Service attack in an update scenario, as an attacker could populate the `registrar` database by creating multiple valid agent registrations with different UUIDs while the version is still &amp;lt; 7.12.0. Then, when the Keylime `registrar` is updated to the 7.12.0 version, any query to the database matching any of the entries populated by the attacker will result in failure.&lt;/p&gt;
&lt;p&gt;### Patches
Users should upgrade to versions &amp;gt;= 7.12.1&lt;/p&gt;
&lt;p&gt;### Workarounds
- Remove the registrar database and re-register all agents&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;Reported by: Anderson Toshiyuki Sasaki/@ansasaki
Patched by: Anderson Toshiyuki Sasaki/@ansasaki&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: keylime&lt;/p&gt;
&lt;p&gt;### Impact
The Keylime `registrar` implemented more strict type checking on version 7.12.0. As a result, when updated to version 7.12.0, the `registrar` will not accept the format of the data previously stored in the database by versions  &amp;gt;= 7.8.0, raising an exception.&lt;/p&gt;
&lt;p&gt;This makes the Keylime `registrar` vulnerable to a Denial-of-Service attack in an update scenario, as an attacker could populate the `registrar` database by creating multiple valid agent registrations with different UUIDs while the version is still &amp;lt; 7.12.0. Then, when the Keylime `registrar` is updated to the 7.12.0 version, any query to the database matching any of the entries populated by the attacker will result in failure.&lt;/p&gt;
&lt;p&gt;### Patches
Users should upgrade to versions &amp;gt;= 7.12.1&lt;/p&gt;
&lt;p&gt;### Workarounds
- Remove the registrar database and re-register all agents&lt;/p&gt;
&lt;p&gt;### Credit&lt;/p&gt;
&lt;p&gt;Reported by: Anderson Toshiyuki Sasaki/@ansasaki
Patched by: Anderson Toshiyuki Sasaki/@ansasaki&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9jxq-5x44-gx23</guid>
    </item>
  </channel>
</rss>
