RHSA-2026:2225: Critical: keylime security update
Critical: keylime security update
Other sources
Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution.Security Fix(es): keylime: Keylime: Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication (CVE-2026-1709) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:2225?
RHSA-2026:2225 has been classified as a critical security vulnerability.
How do I fix RHSA-2026:2225?
To resolve RHSA-2026:2225, update the keylime package to version 7.12.1-11.el10_1.4.
Which systems are affected by RHSA-2026:2225?
RHSA-2026:2225 affects Red Hat Enterprise Linux for Power, IBM z Systems, ARM 64, and x86_64 environments.
What components are impacted by RHSA-2026:2225?
The components impacted by RHSA-2026:2225 include keylime, keylime-registrar, keylime-tenant, keylime-tools, and more.
Are there any additional measures required for RHSA-2026:2225 beyond updating?
After updating to resolve RHSA-2026:2225, it is advisable to review your security configurations and logs for any potential post-update issues.