A race condition exists in the Tang server functionality for key generation and key rotation, which results in a small time window where Tang private keys become readable by other processes on the same host. References: https://bugzilla.redhat.com/show_bug.cgi?id=2180990
Created tang tracking bugs for this issue: Affects: fedora-all [bug 2215313]
Upstream fix: https://github.com/latchset/tang/commit/8dbbed10870378f1b2c3cf3df2ea7edca7617096
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6492 https://access.redhat.com/errata/RHSA-2023:6492
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7022 https://access.redhat.com/errata/RHSA-2023:7022