A flaw was found in Keylime. The Keylime registrar, since version 7.12.0, does not enforce client-side Transport Layer Security (TLS) authentication. This authentication bypass vulnerability allows unauthenticated clients with network access to perform administrative operations, including listing agents, retrieving public Trusted Platform Module (TPM) data, and deleting agents, by connecting without presenting a client certificate.
Keylime Registrar starting from version 7.12.0 stopped enforcing client-side authentication in Transport Layer Security (TLS) protocol. In proper configuration, the client should present a client certificate when establishing a connection, which confirms its identity. Due to this vulnerability (CWE-322: Key Exchange without Entity Authentication), any client with network access can establish a connection without a certificate and perform operations reserved for authenticated entities.
An unauthenticated attacker with network access can enumerate agents, read public Trusted Platform Module (TPM) data, and delete agents, threatening the integrity and availability of the trust verification infrastructure.
Apply patches available from the vendor according to Red Hat advisories: RHSA-2026:2224, RHSA-2026:2225, and RHSA-2026:2298. Additionally, until updates are applied, it is recommended to restrict network access to Keylime Registrar only to trusted hosts using firewall or network segmentation.
Keylime version 7.12.0 and later; Red Hat Enterprise Linux, Red Hat Enterprise Linux EUS, and Red Hat Enterprise Linux for ARM 64 (versions indicated in vendor references)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:HKeylime
APPKeylime< 7.12.0Red Hat Enterprise Linux
OSRedhat10.09.0Red Hat Enterprise Linux Eus
OSRedhat10.0Red Hat Enterprise Linux For Arm 64
OSRedhat10.0_aarch649.0_aarch64Red Hat Enterprise Linux For Arm 64 Eus
OSRedhat10.0_aarch64Red Hat Enterprise Linux For IBM Z Systems
OSRedhat10.0_s390x9.0_s390xRed Hat Enterprise Linux For IBM Z Systems Eus
OSRedhat10.0_s390xRed Hat Enterprise Linux For Power Little Endian
OSRedhat10.0_ppc64le9.0_ppc64leRed Hat Enterprise Linux For Power Little Endian Eus
OSRedhat10.0_ppc64le
Related vulnerabilities
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
Krytyczny heap overwrite w OpenSLP dla VMware ESXi i Horizon DaaS
RCE przez EL injection w RichFaces Framework 3.X — brak uwierzytelnienia
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX