Insecure deserialization In keylime-registrar
Description
An arbitrary code execution vulnerability was discovered in PLY (Python Lex-Yacc). When an application uses PLY's undocumented picklefile parameter to load cached parser data, the library deserializes the pickle file without validation. If an attacker can supply or modify the pickle file being loaded, they can embed malicious code that executes automatically during the deserialization process, potentially allowing them to run arbitrary commands on the affected system.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version |
|---|---|---|
debian 12 | ||
rpm rhel8 | - | |
debian 13 | ||
debian 14 | ||
rpm rhel8 | - | |
rpm rhel10 | - | |
rpm rhel8 | - | |
rpm rhel10 | - | |
rpm rhel9 | - | |
rpm rhel8 | - |
1-10 of 20
10
Aliases
References