PT-2025-47950 · Keylime+3 · Keylime+3

Published

2025-11-24

·

Updated

2026-03-20

·

CVE-2025-13609

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions keylime (affected versions not specified)
Description A flaw exists in keylime that allows an attacker to register a new agent using a different Trusted Platform Module (TPM) device while claiming an existing agent’s unique identifier (UUID). This overwrites the legitimate agent's identity, potentially enabling the attacker to impersonate the compromised agent and bypass security controls.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALSA-2025:23201
ALSA-2025:23210
CVE-2025-13609
GHSA-XH5W-G8GQ-R3V9
OPENSUSE-SU-2025:15811-1
OPENSUSE-SU-2025:20159-1
PYSEC-2025-77
RHSA-2025:23201
RHSA-2025:23210
RHSA-2025:23628
RHSA-2025:23735
RHSA-2025:23852
RHSA-2026:0429
SUSE-SU-2025:21194-1
SUSE-SU-2026:0217-1

Affected Products

Almalinux
Red Hat
Rocky Linux
Keylime