{"id":"CVE-2026-6420","summary":"Keylime: keylime: security bypass due to hardcoded tpm quote nonce","details":"A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.","aliases":["GHSA-q8w6-w55c-ccv5","PYSEC-2026-2548"],"modified":"2026-08-28T11:30:42.676252532Z","published":"2026-05-06T10:19:39.121Z","related":["ALSA-2026:28582","SUSE-SU-2026:22326-1","openSUSE-SU-2026:10779-1","openSUSE-SU-2026:21025-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6420.json","cna_assigner":"redhat","cwe_ids":["CWE-1241"]},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:28582"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-6420"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6420.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6420"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458889"},{"type":"PACKAGE","url":"https://github.com/keylime/keylime"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keylime/keylime","events":[{"introduced":"fc5f04c145beb9c57b12862fd22e8d3bf47fb501"},{"fixed":"9ecfa74ae10953d33e0cd88c4752232b1eca7202"}],"database_specific":{"extracted_events":[{"introduced":"7.14.0"},{"fixed":"7.14.2"}],"source":"AFFECTED_FIELD"}}],"versions":["v7.14.1","v7.14.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6420.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"}]}