CVE-2022-1053Disclosure(fedoraproject / fedora)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and give the verifier an AK of a software TPM. A successful attack breaks the entire chain of trust because a not validated AK is used by the verifier. This issue is worse if the validation happens first and then the agent gets added to the verifier because the timing is easier and the verifier does not validate the regcount entry being equal to 1,

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fedora
  • keylime

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
fedorakeylime

3 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-31: 1Technical Details · 2026-03-31: 103-31
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical flaw (CVE-2022-1053) in an unspecified product could lead to tenant/verifier registrar data inconsistencies, impacting security policy enforcement. Review authentication flows. #infosec #cybersecurity https://www.pulsepatch.io/posts/cve-2022-1053-tenant-verifier-registrar-data-discrepancy

    Post summary

    The message announces a critical flaw (CVE‑2022‑1053) that can lead to tenant/verifier registrar data inconsistencies, potentially undermining security policy enforcement, without providing PoC, exploitation details, or a patch.

    000009
    6 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora34--
OSfedoraprojectfedora35--
OSfedoraprojectfedora36--
Appkeylimekeylime---

Explore more