CVE-2025-13609

8.2

Keylime Project · Keylime

A vulnerability in Keylime allows an attacker with high privileges to register a new agent with an existing UUID, overwriting the legitimate agent's identity and bypassing security controls.

Executive summary

A critical identity spoofing vulnerability in Keylime allows authenticated attackers to hijack agent registrations, potentially leading to unauthorized control over trusted system identities.

Vulnerability

The vulnerability is a CWE-694 flaw involving the use of multiple resources with duplicate identifiers. An attacker with high privileges can register a new Trusted Platform Module device using an existing agent's UUID, causing the system to overwrite the original identity.

Business impact

The ability to spoof an existing agent identity undermines the foundational trust model of the Keylime remote attestation framework. By successfully impersonating a legitimate agent, an attacker could bypass integrity checks, gain unauthorized access to sensitive system telemetry, or manipulate security policies. Given the CVSS score of 8.2, this vulnerability represents a high risk to environment integrity, particularly in regulated or high security infrastructure where remote attestation is a primary control.

Remediation

Immediate Action: Update Keylime to version 7.13.0 or apply the specific security errata provided by Red Hat for RHEL 9 and 10 environments as linked in the vendor references.

Proactive Monitoring: Review agent registration logs for unexpected UUID collisions or unauthorized registration attempts from unrecognized TPM devices.

Compensating Controls: Ensure that access to the Keylime controller is restricted to highly trusted administrators, as the exploit requires high privileges to execute successfully.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The identity spoofing capability inherent in this flaw poses a significant threat to the reliability of remote attestation. Organizations utilizing Keylime to manage trusted platform identities must prioritize the application of the vendor patches to prevent potential identity hijacking and subsequent security control bypasses.

More Keylime Project CVEs

Sources