The vendor explicitly identifies these products as affected by this CVE.
- openshift-sandboxed-containers/osc-podvm-payload-rhel9 as a component of Confidential Compute Attestation
- clevis-pin-trustee.src as a component of Red Hat Enterprise Linux 10
- trustee-kbs as a component of Red Hat Enterprise Linux 10
- clevis-pin-trustee.src as a component of Red Hat Enterprise Linux 9
- kata-containers as a component of Red Hat OpenShift Container Platform 4
- kata-containers.src as a component of Red Hat OpenShift Container Platform 4
- rhtpa/rhtpa-trustification-service-rhel9 as a component of Red Hat Trusted Profile Analyzer
- Summary
- A flaw was found in aws-lc, a cryptographic library. An unauthenticated attacker can exploit improper certificate validation within the `PKCS7_verify()` function. This allows them to bypass the verification process for certificate chains when handling PKCS7 objects that contain multiple digital signers, except for the last one. The primary consequence is a compromise of integrity, as the system may incorrectly trust unverified certificates.
- Remediation
- Red Hat Trusted Artifact Signer simplifies cryptographic signing and verifying of software artifacts such as container images, binaries and source code changes. It is a self-managed on-premise deployment of the Sigstore project available at https://sigstore.dev Platform Engineers, Software Developers and Security Professionals may use RHTAS to ensure the integrity, transparency and assurance of their organization's software supply chain. For details on using the operator, refer to the product documentation at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3 You can find the release notes for this version of Red Hat Trusted Artifact Signer at https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/index
