View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2022-3500 severity moderate: SUSE including 15 source package names (keylime-6.5.1-1.el9_1, keylime-agent-6.3.2-150400.4.14.1, …), 54 product×package rows across 7 product lines (SUSE Liberty Linux 9, SUSE Linux Enterprise Module for Basesystem 15 SP4, … (7 product lines)): Fixed 54.
A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.