Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:2225

Опубликовано: 11 фев. 2026
Источник: rocky
Оценка: Critical

Описание

Critical: keylime security update

Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution.

Security Fix(es):

  • keylime: Keylime: Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication (CVE-2026-1709)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
keylimex86_6411.el10_1.4keylime-7.12.1-11.el10_1.4.x86_64.rpm
keylime-registrarx86_6411.el10_1.4keylime-registrar-7.12.1-11.el10_1.4.x86_64.rpm
python3-keylimex86_6411.el10_1.4python3-keylime-7.12.1-11.el10_1.4.x86_64.rpm
keylime-selinuxnoarch11.el10_1.4keylime-selinux-7.12.1-11.el10_1.4.noarch.rpm
keylime-tenantx86_6411.el10_1.4keylime-tenant-7.12.1-11.el10_1.4.x86_64.rpm
keylime-toolsx86_6411.el10_1.4keylime-tools-7.12.1-11.el10_1.4.x86_64.rpm
keylime-verifierx86_6411.el10_1.4keylime-verifier-7.12.1-11.el10_1.4.x86_64.rpm
keylime-basex86_6411.el10_1.4keylime-base-7.12.1-11.el10_1.4.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.4
ubuntu
около 2 месяцев назад

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

CVSS3: 9.4
redhat
около 2 месяцев назад

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

CVSS3: 9.4
nvd
около 2 месяцев назад

A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.

rocky
около 2 месяцев назад

Critical: keylime security update

CVSS3: 9.4
github
около 2 месяцев назад

Keylime Missing Authentication for Critical Function and Improper Authentication