Описание
ELSA-2026-28582: keylime security update (MODERATE)
[7.14.1-6]
- keylime: Fix hardcoded attestation challenge nonce (CVE-2026-6420) [RHEL-168795]
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
keylime
7.14.1-5.el10_2.1
keylime-base
7.14.1-5.el10_2.1
keylime-registrar
7.14.1-5.el10_2.1
keylime-selinux
7.14.1-5.el10_2.1
keylime-tenant
7.14.1-5.el10_2.1
keylime-tools
7.14.1-5.el10_2.1
keylime-verifier
7.14.1-5.el10_2.1
python3-keylime
7.14.1-5.el10_2.1
Oracle Linux x86_64
keylime
7.14.1-5.el10_2.1
keylime-base
7.14.1-5.el10_2.1
keylime-registrar
7.14.1-5.el10_2.1
keylime-selinux
7.14.1-5.el10_2.1
keylime-tenant
7.14.1-5.el10_2.1
keylime-tools
7.14.1-5.el10_2.1
keylime-verifier
7.14.1-5.el10_2.1
python3-keylime
7.14.1-5.el10_2.1
Связанные CVE
Связанные уязвимости
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.