Bug 2416761 (CVE-2025-13609) - CVE-2025-13609 keylime: Keylime: Registrar allows identity takeover via duplicate UUID registration
Summary: CVE-2025-13609 keylime: Keylime: Registrar allows identity takeover via dupli...
Keywords:
Status: NEW
Alias: CVE-2025-13609
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2416806 2416807 2416805
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-11-24 14:59 UTC by OSIDB Bzimport
Modified: 2026-01-12 02:01 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:23201 0 None None None 2025-12-16 08:32:13 UTC
Red Hat Product Errata RHSA-2025:23210 0 None None None 2025-12-16 19:23:57 UTC
Red Hat Product Errata RHSA-2025:23628 0 None None None 2025-12-18 10:06:22 UTC
Red Hat Product Errata RHSA-2025:23735 0 None None None 2025-12-22 01:26:08 UTC
Red Hat Product Errata RHSA-2025:23852 0 None None None 2025-12-22 11:38:40 UTC
Red Hat Product Errata RHSA-2026:0429 0 None None None 2026-01-12 02:01:09 UTC

Description OSIDB Bzimport 2025-11-24 14:59:01 UTC
The Keylime registrar allows registration of another agent (different TPM device, different EK certificate) with a duplicate UUID.
This presents a critical security vulnerability that allows an attacker to take over an existing agent's identity by re-registering with the same UUID though a different TPM's EK certificate.

Comment 3 errata-xmlrpc 2025-12-16 08:32:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:23201 https://access.redhat.com/errata/RHSA-2025:23201

Comment 4 errata-xmlrpc 2025-12-16 19:23:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:23210 https://access.redhat.com/errata/RHSA-2025:23210

Comment 5 errata-xmlrpc 2025-12-18 10:06:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2025:23628 https://access.redhat.com/errata/RHSA-2025:23628

Comment 6 errata-xmlrpc 2025-12-22 01:26:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:23735 https://access.redhat.com/errata/RHSA-2025:23735

Comment 7 errata-xmlrpc 2025-12-22 11:38:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:23852 https://access.redhat.com/errata/RHSA-2025:23852

Comment 8 errata-xmlrpc 2026-01-12 02:01:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:0429 https://access.redhat.com/errata/RHSA-2026:0429


Note You need to log in before you can comment on or make changes to this bug.