Description
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3648-1 | tang security update |
EUVD |
EUVD-2023-23900 | A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host. |
Ubuntu USN |
USN-6489-1 | Tang vulnerability |
References
History
Tue, 01 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-02-13T16:39:29.669Z
Reserved: 2023-03-28T15:03:04.864Z
Link: CVE-2023-1672
Updated: 2024-08-02T05:57:24.884Z
Status : Modified
Published: 2023-07-11T12:15:09.520
Modified: 2026-06-17T05:28:29.497
Link: CVE-2023-1672
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Debian DLA
EUVD
Ubuntu USN