Количество 7
Количество 7
GHSA-q8w6-w55c-ccv5
Keylime has a hardcoded attestation challenge nonce that allows replay attacks
CVE-2026-6420
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.
CVE-2026-6420
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.
CVE-2026-6420
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.
openSUSE-SU-2026:21025-1
Security update for keylime
RLSA-2026:28582
Moderate: keylime security update
ELSA-2026-28582
ELSA-2026-28582: keylime security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-q8w6-w55c-ccv5 Keylime has a hardcoded attestation challenge nonce that allows replay attacks | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-6420 A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment. | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-6420 A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment. | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-6420 A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment. | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21025-1 Security update for keylime | 0% Низкий | около 1 месяца назад | ||
RLSA-2026:28582 Moderate: keylime security update | 0% Низкий | около 1 месяца назад | ||
ELSA-2026-28582 ELSA-2026-28582: keylime security update (MODERATE) | 16 дней назад |
Уязвимостей на страницу