REDHAT-BUG-2416761: High severity Keylime Keylime registrar vulnerability
The Keylime registrar allows registration of another agent (different TPM device, different EK certificate) with a duplicate UUID. This presents a critical security vulnerability that allows an attacker to take over an existing agent's identity by re-registering with the same UUID though a different TPM's EK certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2416761?
The severity of REDHAT-BUG-2416761 is critical as it allows an attacker to take over an existing agent's identity.
How do I fix REDHAT-BUG-2416761?
To fix REDHAT-BUG-2416761, ensure that unique UUIDs are enforced for each agent during the registration process.
What type of attack does REDHAT-BUG-2416761 enable?
REDHAT-BUG-2416761 enables identity theft where an attacker can impersonate a legitimate agent by using a duplicate UUID.
What kind of systems are affected by REDHAT-BUG-2416761?
Systems utilizing the Keylime registrar for agent registration that fail to enforce unique UUIDs are affected by REDHAT-BUG-2416761.
Is there a workaround for REDHAT-BUG-2416761?
Currently, the recommended workaround is to manually check and verify UUIDs during the agent registration process until a patch is applied.