The Keylime registrar allows registration of another agent (different TPM device, different EK certificate) with a duplicate UUID. This presents a critical security vulnerability that allows an attacker to take over an existing agent's identity by re-registering with the same UUID though a different TPM's EK certificate.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:23201 https://access.redhat.com/errata/RHSA-2025:23201
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:23210 https://access.redhat.com/errata/RHSA-2025:23210
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2025:23628 https://access.redhat.com/errata/RHSA-2025:23628
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:23735 https://access.redhat.com/errata/RHSA-2025:23735
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:23852 https://access.redhat.com/errata/RHSA-2025:23852
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:0429 https://access.redhat.com/errata/RHSA-2026:0429