⚠ Withdrawn by GitHub Security Advisories

Withdrawn: May 11, 2026

GHSA-wc6p-4gwj-jcr8MediumCVSS 6.3Disclosed before NVD

Duplicate Advisory: Keylime has a hardcoded attestation challenge nonce that allows replay attacks

Published
May 6, 2026
Last Modified
June 24, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-q8w6-w55c-ccv5. This link is maintained to preserve external references.

Original Description

A flaw was found in Keylime. An attacker with root access on an enrolled monitored machine, where the Keylime agent runs, can exploit a vulnerability in the Keylime verifier. The verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows the attacker to stockpile valid TPM quotes and replay them to evade detection after compromising the system. This issue affects only the push model deployment.

🎯 Affected products1

  • pip/keylime:>= 7.14.0, <= 7.14.1

🔗 References (5)