Junglewise Threat Intelligence

CVE-2025-13609: Keylime identity takeover via duplicate UUID registration in Registrar

CVE-2025-13609 · Severity: high · CVSS 8.2 · Published 2025-11-24

Technologies: Red Hat Enterprise Linux 10, keylime (PyPI), Red Hat Enterprise Linux 9. Vendors: Red Hat, PyPI.

Executive brief

Keylime is a security tool used to verify the integrity of remote computers and cloud servers using hardware-based trust. A vulnerability in its registration component allows an attacker to register a malicious device using the identity of an existing, legitimate server. This allows the attacker to impersonate trusted systems, potentially bypassing security controls and gaining unauthorized access to sensitive environments.

Technical details

A vulnerability classified as CWE-694 (Use of Multiple Resources with Duplicate Identifier) exists in the Keylime Registrar. An attacker with sufficient privileges can register a new agent using a different Trusted Platform Module (TPM) device while claiming the Universally Unique Identifier (UUID) of an existing, legitimate agent. The Registrar fails to properly validate the uniqueness of the UUID against the associated TPM identity, allowing the attacker to overwrite the legitimate agent's record. This enables the attacker to impersonate the compromised agent during attestation processes and bypass security controls. The issue is addressed in Keylime version 7.14.0 and various Red Hat package updates.

Affected products

  • Keylime Project keylime < 7.14.0
  • Red Hat Red Hat Enterprise Linux 9 < 7.12.1-11.el9_7.3
  • Red Hat Red Hat Enterprise Linux 10 < 7.12.1-11.el10_1.3

Timeline

  • 2025-11-24: disclosed
  • 2025-12-15: patched: Red Hat released security updates for RHEL 9 and 10.

References

Related threats