{"id":"CVE-2023-1672","summary":"Race condition exists in the key generation and rotation functionality","details":"A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.","modified":"2026-08-12T13:33:49.154366Z","published":"2023-07-11T11:47:35.363Z","related":["ALSA-2023:6492","ALSA-2023:7022"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-362"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1672.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/11/msg00004.html"},{"type":"WEB","url":"https://packages.fedoraproject.org/"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/06/15/1"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2023-1672"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1672.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1672"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2180999"},{"type":"FIX","url":"https://github.com/latchset/tang/commit/8dbbed10870378f1b2c3cf3df2ea7edca7617096"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/latchset/tang","events":[{"introduced":"0"},{"fixed":"100265e32f56e33c8120fca83de419155ac8db5e"},{"fixed":"8dbbed10870378f1b2c3cf3df2ea7edca7617096"}],"database_specific":{"cpe":"cpe:2.3:a:tang_project:tang:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"14"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v13","v12","v11","v10","v9","v8","v7","v6","v5","v4","v3","v2","v1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1672.json","vanir_signatures_modified":"2026-08-12T13:33:49Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/latchset/tang/commit/8dbbed10870378f1b2c3cf3df2ea7edca7617096","target":{"function":"create_new_keys","file":"src/keys.c"},"deprecated":false,"digest":{"function_hash":"149947170351878071834100038294147802107","length":863},"id":"CVE-2023-1672-c6f7fc11","signature_type":"Function"},{"target":{"file":"src/keys.c"},"deprecated":false,"digest":{"line_hashes":["290682886615114646841198991571939427789","191331018568499987420945389041944099685","100594790634125479673057945341284191592","121505816812480176417552743829426362398"],"threshold":0.9},"id":"CVE-2023-1672-d128fd0c","signature_type":"Line","signature_version":"v1","source":"https://github.com/latchset/tang/commit/8dbbed10870378f1b2c3cf3df2ea7edca7617096"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}