A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tang | Nov 16, 2023 | Jul 11, 2023 |
| Centos_linux | — | Upgrade tang-debugsourceUpgrade tangUpgrade tang-debuginfo | Nov 8, 2023 | Jul 11, 2023 |
| Debian | — | Upgrade tang | Nov 8, 2023 | Jul 11, 2023 |
| Oracle_linux | — | Upgrade tang | Nov 16, 2023 | Jun 7, 2023 |
| Redhat_linux | — | Upgrade tang-debugsourceUpgrade tang-debuginfoNo solution existsUpgrade tang | Nov 8, 2023 | Jul 11, 2023 |
| Ubuntu | — | Upgrade tang-commonUpgrade tang (Ubuntu Pro)Upgrade tang | Nov 21, 2023 | Jul 11, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub