RHSA-2026:2298: Critical: keylime security update
Critical: keylime security update
Other sources
Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution.Security Fix(es): keylime: Keylime: Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication (CVE-2026-1709) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:2298?
RHSA-2026:2298 is classified as a critical severity vulnerability.
How do I fix RHSA-2026:2298?
To fix RHSA-2026:2298, update the keylime package to version 7.12.1-2.el10_0.5 or later.
What type of vulnerability is RHSA-2026:2298?
RHSA-2026:2298 addresses an authentication bypass vulnerability that allows unauthorized administrative operations.
Which software is affected by RHSA-2026:2298?
RHSA-2026:2298 affects multiple versions of Red Hat Enterprise Linux, including x86_64, ARM 64, and IBM z Systems.
What is Keylime in the context of RHSA-2026:2298?
Keylime is a TPM-based solution for remote boot attestation and runtime integrity measurement.