{"id":"GHSA-wc6p-4gwj-jcr8","summary":"Duplicate Advisory: Keylime has a hardcoded attestation challenge nonce that allows replay attacks","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-q8w6-w55c-ccv5. This link is maintained to preserve external references.\n\n### Original Description\nA flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.","modified":"2026-06-24T03:45:23.749946026Z","published":"2026-05-06T12:30:28Z","withdrawn":"2026-05-11T14:08:50Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-11T14:08:50Z","nvd_published_at":"2026-05-06T11:16:05Z","cwe_ids":["CWE-1241"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6420"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:28582"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-6420"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2458889"}],"affected":[{"package":{"name":"keylime","ecosystem":"PyPI","purl":"pkg:pypi/keylime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.14.0"},{"fixed":"7.14.2"}]}],"versions":["7.14.0","7.14.1"],"database_specific":{"last_known_affected_version_range":"\u003c= 7.14.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wc6p-4gwj-jcr8/GHSA-wc6p-4gwj-jcr8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"}]}