oss-sec mailing list archives

CVE-2023-1672: race condition in Tang exposes private keys to other processes


From: Brian McDermott <bmcdermott () census-labs com>
Date: Thu, 15 Jun 2023 12:56:52 +0100

Hello all,

Tang (https://github.com/latchset/tang) is an open source project that is used to bind data to network presence. It is commonly used along with Clevis clients to provide for unattended LUKS decryption of server storage volumes within the realms of a network, where a trusted Tang server is situated.

CENSUS identified that the Tang software in versions 11, 12 and 13 (and possibly previous versions) is vulnerable to a form of race condition, where the Tang private keys become exposed for a small time window to other users on the same host. The issue is tracked as CVE-2023-1672. More information regarding the vulnerability can be found here: https://census-labs.com/news/2023/06/15/race-tang/

Users are recommended to upgrade to Tang version 14 where the issue has been sufficiently addressed.

Best regards,

Brian McDermott

--
Brian McDermott
Jr IT Security Professional Intern
Add: SYNGROU AVENUE 128, Athens 11745, Greece
Mob: +30 6944 435541
Tel: +30 210 2208989-90
https://census-labs.com -- IT Security Works

CONFIDENTIALITY NOTICE
The contents of this email message and any attachments are intended solely for the
addressee(s) and might contain confidential and/or privileged information and might
be legally protected from disclosure. If you are not the intended recipient of this
message or this message has been addressed to you in error, please immediately notify
the sender and delete any copies of it; you are hereby notified that any use, copying
or storage of this message or its attachments is strictly prohibited.

Attachment: OpenPGP_0x68BA3525BB668B19.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature
Description: OpenPGP digital signature


Current thread: