Bug 2416761 (CVE-2025-13609) - CVE-2025-13609 keylime: Keylime: Registrar allows identity takeover via duplicate UUID registration
Summary: CVE-2025-13609 keylime: Keylime: Registrar allows identity takeover via dupli...
Keywords:
Status: NEW
Alias: CVE-2025-13609
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2416805 2416806 2416807
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-11-24 14:59 UTC by OSIDB Bzimport
Modified: 2025-11-24 17:46 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-11-24 14:59:01 UTC
The Keylime registrar allows registration of another agent (different TPM device, different EK certificate) with a duplicate UUID.
This presents a critical security vulnerability that allows an attacker to take over an existing agent's identity by re-registering with the same UUID though a different TPM's EK certificate.


Note You need to log in before you can comment on or make changes to this bug.