This advisory has been withdrawn because it is a duplicate of GHSA-q8w6-w55c-ccv5. This link is maintained to preserve external references.
A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.
{
"cwe_ids": [
"CWE-1241"
],
"github_reviewed": true,
"github_reviewed_at": "2026-05-11T14:08:50Z",
"nvd_published_at": "2026-05-06T11:16:05Z",
"severity": "MODERATE"
}