Medium severity5.3NVD Advisory· Published Jul 11, 2023· Updated Jun 17, 2026
CVE-2023-1672
CVE-2023-1672
Description
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:/o:redhat:enterprise_linux:7+ 4 more
- cpe:/o:redhat:enterprise_linux:7
- cpe:/o:redhat:enterprise_linux:8
- cpe:/o:redhat:enterprise_linux:9
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- github.com/latchset/tang/commit/8dbbed10870378f1b2c3cf3df2ea7edca7617096nvdPatch
- www.openwall.com/lists/oss-security/2023/06/15/1nvdExploitMailing ListThird Party Advisory
- access.redhat.com/security/cve/CVE-2023-1672nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/11/msg00004.htmlnvd
News mentions
0No linked articles in our index yet.