High severity7.5NVD Advisory· Published Jul 24, 2023· Updated Jun 17, 2026
CVE-2023-38200
CVE-2023-38200
Description
A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
keylimePyPI | < 7.4.0 | 7.4.0 |
Affected products
22- osv-coords12 versionspkg:rpm/suse/keylime&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/opensuse/keylime&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/keylime&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/keylime&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:pypi/keylimepkg:rpm/almalinux/keylimepkg:rpm/almalinux/keylime-basepkg:rpm/almalinux/keylime-registrarpkg:rpm/almalinux/keylime-selinuxpkg:rpm/almalinux/keylime-tenantpkg:rpm/almalinux/keylime-verifierpkg:rpm/almalinux/python3-keylime
< 6.3.2-150400.4.17.1+ 11 more
- (no CPE)range: < 6.3.2-150400.4.17.1
- (no CPE)range: < 6.3.2-150400.4.17.1
- (no CPE)range: < 6.3.2-150400.4.17.1
- (no CPE)range: < 6.3.2-150400.4.17.1
- (no CPE)range: < 7.4.0
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
- (no CPE)range: < 6.5.2-6.el9_2.alma.1
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
- cpe:/a:redhat:enterprise_linux:9::appstreamrange: 0:6.5.2-6.el9_2
- cpe:2.3:o:redhat:enterprise_linux_eus:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems_eus:9.2_s390x:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:9.0_ppc64le:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian_eus:9.0_ppc64le:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- github.com/keylime/keylime/pull/1421nvdPatchWEB
- access.redhat.com/errata/RHSA-2023:5080nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2023-38200nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-pg75-v6fp-8q59ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-38200ghsaADVISORY
- github.com/keylime/keylime/commit/c68d8f0b7ea549c12b6956ab0f3c28ae0360ae17ghsaWEB
- github.com/keylime/keylime/releases/tag/v7.4.0ghsaWEB
- github.com/keylime/keylime/security/advisories/GHSA-pg75-v6fp-8q59ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ZIZZB5NHNCS5D2AEH3ZAO6OQC72IK7WS/nvd
News mentions
0No linked articles in our index yet.