PT-2026-37443 · Keylime · Keylime

CVE-2026-6420

·

Published

2026-05-06

·

Updated

2026-07-13

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Keylime (affected versions not specified)
Description A flaw in the Keylime verifier allows an attacker with root access on an enrolled monitored machine to bypass security. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation—a process used to verify the integrity of a system—instead of a cryptographically random value. This enables an attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue specifically affects the push model deployment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6420
GHSA-Q8W6-W55C-CCV5
GHSA-WC6P-4GWJ-JCR8
OPENSUSE-SU-2026:10779-1
OPENSUSE-SU-2026:21025-1
PYSEC-2026-2548
RHSA-2026:28582
SUSE-SU-2026:22326-1

Affected Products

Keylime