Bug 2416761 (CVE-2025-13609)
| Summary: | CVE-2025-13609 keylime: Keylime: Registrar allows identity takeover via duplicate UUID registration | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | security-response-team |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This action overwrites the legitimate agent's identity, enabling the attacker to impersonate the compromised agent and potentially bypass security controls.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2416806, 2416807, 2416805 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2025-11-24 14:59:01 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:23201 https://access.redhat.com/errata/RHSA-2025:23201 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:23210 https://access.redhat.com/errata/RHSA-2025:23210 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2025:23628 https://access.redhat.com/errata/RHSA-2025:23628 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:23735 https://access.redhat.com/errata/RHSA-2025:23735 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:23852 https://access.redhat.com/errata/RHSA-2025:23852 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:0429 https://access.redhat.com/errata/RHSA-2026:0429 |