Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2025:20057-1 — rust-keylime (CVE-2024-43806 +1 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for rust-keylime

This update for rust-keylime fixes the following issues:

  • Update vendored crates (CVE-2024-43806, bsc#1229952, bsc#1230029)
  • rustix 0.37.25
  • rustix 0.38.34
  • shlex 1.3.0
  • Update to version 0.2.6+13:
  • Enable test functional/iak-idevid-persisted-and-protected
  • build(deps): bump uuid from 1.7.0 to 1.10.0
  • build(deps): bump openssl from 0.10.64 to 0.10.66
  • keylime-agent/src/revocation: Fix comment indentation
  • keylime/crypto: Fix indentation of documentation comment
  • build(deps): bump thiserror from 1.0.59 to 1.0.63
  • build(deps): bump serde_json from 1.0.116 to 1.0.120
  • dependabot: Extend to also monitor workflow actions
  • ci: Disable Packit CI on CentOS Stream 9
  • ci: use CODECOV_TOKEN when submitting coverage data
  • revocation: Use into() for unfallible transformation
  • secure_mount: Fix possible infinite loop
  • error: Rename enum variants to avoid clippy warning
  • Update to version 0.2.6~0:
  • Bump version to 0.2.6
  • build(deps): bump libc from 0.2.153 to 0.2.155
  • build(deps): bump serde from 1.0.196 to 1.0.203
  • rpm/fedora: Update rust macro usage
  • config: Support hostnames in registrar_ip option
  • added use of persisted IAK and IDevID and authorisation values
  • config changes
  • Adding /agent/info API to agent
  • Fix leftover 'unnecessary qualification' warnings on tests
  • Update to version 0.2.5~4:
  • Fix 'unnecessary qualification' warnings
  • fix IAK template to match IDevID
  • rpm: fix COPR RPMs build for centos-stream-10
  • Build COPR RPMs for centos-stream-10
  • Update to version 0.2.5~0:
  • Bump version to 0.2.5
  • cargo: Relax required version for pest crate
  • build(deps): bump log from 0.4.20 to 0.4.21
  • build(deps): bump thiserror from 1.0.56 to 1.0.59
  • actix-web update moves rustls as feature (bsc#1223234, CVE-2024-32650)
  • Update to version 0.2.4~39:
  • build(deps): bump openssl from 0.10.63 to 0.10.64
  • build(deps): bump h2 from 0.3.24 to 0.3.26
  • build(deps): bump serde_json from 1.0.107 to 1.0.116
  • build(deps): bump actix-web from 4.4.1 to 4.5.1
  • crypto: Enable TLS 1.3
  • build(deps): bump tempfile from 3.9.0 to 3.10.1
  • build(deps): bump mio from 0.8.4 to 0.8.11
  • enable hex values to be used for tpm_ownerpassword
  • config: Support IPv6 with or without brackets
  • keylime: Implement a simple IP parser to remove brackets
  • crypto: Implement CertificateBuilder to generate certificates
  • tests: Fix coverage download by supporting arbitrary URL
  • cargo: Add testing feature to keylime library
  • Set X509 SAN with local DNSname/IP/IPv6
  • Include newest Node20 versions for Github actions
  • tpm: Add unit test for uncovered public functions
  • crypto: Implement ECC key generation support
  • crypto: Add test for match_cert_to_template()
  • Fix minor typo, format and remove end whitespaces
  • crypto: Make error types less specific
  • tests/run.sh: Run tarpaulin with a single thread
  • payloads: Remove explicit drop of channel transmitter
  • crypto: Move to keylime library
  • crypto: Add specific type for every possible error
  • tpm: Rename origin of error as source in structures
  • list_parser: Add source for error for backtrace
  • algorithms: Make errors more specific
  • typo fix for default path to measured boot log file
  • README: remove mentions of libarchive as a dependency
  • Dockerfile.wolfi: Update clang to version 17
  • docker: Remove libarchive as a dependency
  • rpm: Remove libarchive from dependencies
  • cargo: Replace compress-tools with zip crate
  • cargo: Bump ahash to version 0.8.7
  • build(deps): bump serde from 1.0.195 to 1.0.196
  • build(deps): bump libc from 0.2.152 to 0.2.153
  • build(deps): bump reqwest from 0.11.23 to 0.11.24
  • docker: Install configuration file in the correct path
  • config: Make IAK/IDevID disabled by default
  • Update to version 0.2.4+git.1706692574.a744517:
  • Bump version to 0.2.4
  • build(deps): bump uuid from 1.4.1 to 1.7.0
  • keylime-agent.conf: Allow setting event logs paths
  • Mutable log paths: allow IMA and MBA log paths to be overridden by keylime configuration.
  • workflows: Update checkout action to version 4
  • build(deps): bump serde from 1.0.188 to 1.0.195
  • build(deps): bump pest_derive from 2.7.0 to 2.7.6
  • build(deps): bump openssl from 0.10.62 to 0.10.63
  • build(deps): bump config from 0.13.3 to 0.13.4
  • build(deps): bump base64 from 0.21.4 to 0.21.7
  • build(deps): bump tempfile from 3.8.0 to 3.9.0
  • build(deps): bump pest from 2.7.0 to 2.7.6
  • build(deps): bump actix-web from 4.4.0 to 4.4.1
  • build(deps): bump reqwest from 0.11.22 to 0.11.23
  • build(deps): bump h2 from 0.3.17 to 0.3.24
  • build(deps): bump shlex from 1.1.0 to 1.3.0
  • cargo: Bump tss-esapi to version 7.4.0
  • workflows: Fix keylime-bot token usage
  • tpm: Add error context for every possible error
  • tpm: Add AlgorithmError to TpmError
  • detect idevid template from certificates

Affected software

SUSE-SU-2025:20057-1 is recorded against 1 package.

  • rust-keylime (fixed in 0.2.6+13-1.1)

Timeline and source

Published on 3 February 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-02-03
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
rust-keylime 0.2.6+13-1.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20057-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20057-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.