Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23852 - Security Advisory
Issued:
2025-12-22
Updated:
2025-12-22

RHSA-2025:23852 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: keylime security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for keylime is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution.

Security Fix(es):

  • keylime: Keylime: Registrar allows identity takeover via duplicate UUID registration (CVE-2025-13609)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x

Fixes

  • BZ - 2416761 - CVE-2025-13609 keylime: Keylime: Registrar allows identity takeover via duplicate UUID registration

CVEs

  • CVE-2025-13609

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
x86_64
keylime-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 18a7144241c16c8f1334f77b6357304b9879bb346cbdbbec82cf5f51765d695e
keylime-base-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: de14f72afdf00b31a573889c84ad5d3ddf25f8482d019d5d5a093d4854703a7c
keylime-registrar-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 717bf7640b0910f1954e2c6f931bbda79a92096d313091d28faa688e2edb0f5d
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 54ee7f99596de339ae2fe097452722cee32421af468627400875ecd00dea58c4
keylime-verifier-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: e45bd1a8ca57cf5f55ca8b607fbb8464d5f24a0371aaf2b21cb2ce5f010a8433
python3-keylime-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 15bce15246c8a6ff00ace9fa4e08e99baa1998ffa9f10046553485c0c1fae082

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
x86_64
keylime-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 18a7144241c16c8f1334f77b6357304b9879bb346cbdbbec82cf5f51765d695e
keylime-base-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: de14f72afdf00b31a573889c84ad5d3ddf25f8482d019d5d5a093d4854703a7c
keylime-registrar-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 717bf7640b0910f1954e2c6f931bbda79a92096d313091d28faa688e2edb0f5d
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 54ee7f99596de339ae2fe097452722cee32421af468627400875ecd00dea58c4
keylime-verifier-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: e45bd1a8ca57cf5f55ca8b607fbb8464d5f24a0371aaf2b21cb2ce5f010a8433
python3-keylime-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 15bce15246c8a6ff00ace9fa4e08e99baa1998ffa9f10046553485c0c1fae082

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
s390x
keylime-7.3.0-13.el9_4.1.s390x.rpm SHA-256: 2d1d6642bc7a9f478a09d44ba7133108447e3643664698d2153634168c2600ca
keylime-base-7.3.0-13.el9_4.1.s390x.rpm SHA-256: e436c1fdf85d08ede37cb37fa9559aa0c94c095445660c34232ebc39ce33082b
keylime-registrar-7.3.0-13.el9_4.1.s390x.rpm SHA-256: ea9c565a614b8b42f93cb510e6500b8617037462725afbad79adcb74f40fff5a
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.s390x.rpm SHA-256: 95e144bb4b3ed8614830991645b54854823d95488e3e087023dabac3ca33916d
keylime-verifier-7.3.0-13.el9_4.1.s390x.rpm SHA-256: 0688c387f69ee7c5302f71ac4c281b265b19957a26115d14647992ff9c4428fd
python3-keylime-7.3.0-13.el9_4.1.s390x.rpm SHA-256: 285eaedf9ab20cbc2a061f9a888d3137b3d432ef0bd3040ff59b19fb5cf2e635

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
ppc64le
keylime-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: 79a90c1a1f05835e682bb07d74e8c2731922ff19ec27d6472621e23ffc067f39
keylime-base-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: 3c22d7135e5f95ac3832ca60f67166454b2feea23cc209c494697adf85595929
keylime-registrar-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: c3ae1af0c3badb990fd788069d2776841fced27e6c3ef72db309f19968cb5809
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: 84cae03abdbb7255258314f7db9c12e73351d136e12bcdd2a604e728747c28c6
keylime-verifier-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: dc541fb8c7cc9cfd81526d20577b736c38d04fd09dd84972e75473ff09111d19
python3-keylime-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: 65776fda4d45eaf5addbaa3af7ed2f70103e6c30624fd783678bc018ef56c319

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
aarch64
keylime-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: f6179039e99b03df955580a4f1c63c6dde537ee90d709e5f5eb57300bc4477e6
keylime-base-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: 02d7bae74d4e88f7780cef8848c305abb02144a876ea4af04c9f4ec1ce11363b
keylime-registrar-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: 110f97eb66f42a8cc52bcadb2f429079f00af302a79d33bf56c69918b3207218
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: 3e5b733da4edf114e7d2faf86b656eb54c639aa12e48961655f79cc1269ba27a
keylime-verifier-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: 6effad108dbf14809dee7d67f13e1258ce8efeca5b7e4812d3aeff6ab89d7689
python3-keylime-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: dfca1be7ce2b613eb82ead68cfd9f4818300e88e66ea799792b6925581487a7e

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
ppc64le
keylime-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: 79a90c1a1f05835e682bb07d74e8c2731922ff19ec27d6472621e23ffc067f39
keylime-base-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: 3c22d7135e5f95ac3832ca60f67166454b2feea23cc209c494697adf85595929
keylime-registrar-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: c3ae1af0c3badb990fd788069d2776841fced27e6c3ef72db309f19968cb5809
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: 84cae03abdbb7255258314f7db9c12e73351d136e12bcdd2a604e728747c28c6
keylime-verifier-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: dc541fb8c7cc9cfd81526d20577b736c38d04fd09dd84972e75473ff09111d19
python3-keylime-7.3.0-13.el9_4.1.ppc64le.rpm SHA-256: 65776fda4d45eaf5addbaa3af7ed2f70103e6c30624fd783678bc018ef56c319

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
x86_64
keylime-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 18a7144241c16c8f1334f77b6357304b9879bb346cbdbbec82cf5f51765d695e
keylime-base-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: de14f72afdf00b31a573889c84ad5d3ddf25f8482d019d5d5a093d4854703a7c
keylime-registrar-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 717bf7640b0910f1954e2c6f931bbda79a92096d313091d28faa688e2edb0f5d
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 54ee7f99596de339ae2fe097452722cee32421af468627400875ecd00dea58c4
keylime-verifier-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: e45bd1a8ca57cf5f55ca8b607fbb8464d5f24a0371aaf2b21cb2ce5f010a8433
python3-keylime-7.3.0-13.el9_4.1.x86_64.rpm SHA-256: 15bce15246c8a6ff00ace9fa4e08e99baa1998ffa9f10046553485c0c1fae082

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
aarch64
keylime-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: f6179039e99b03df955580a4f1c63c6dde537ee90d709e5f5eb57300bc4477e6
keylime-base-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: 02d7bae74d4e88f7780cef8848c305abb02144a876ea4af04c9f4ec1ce11363b
keylime-registrar-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: 110f97eb66f42a8cc52bcadb2f429079f00af302a79d33bf56c69918b3207218
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: 3e5b733da4edf114e7d2faf86b656eb54c639aa12e48961655f79cc1269ba27a
keylime-verifier-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: 6effad108dbf14809dee7d67f13e1258ce8efeca5b7e4812d3aeff6ab89d7689
python3-keylime-7.3.0-13.el9_4.1.aarch64.rpm SHA-256: dfca1be7ce2b613eb82ead68cfd9f4818300e88e66ea799792b6925581487a7e

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
keylime-7.3.0-13.el9_4.1.src.rpm SHA-256: 013d534f3f1be0173ecd9d5cab823fa33126aadce2409cc58b91e8b07ad4a819
s390x
keylime-7.3.0-13.el9_4.1.s390x.rpm SHA-256: 2d1d6642bc7a9f478a09d44ba7133108447e3643664698d2153634168c2600ca
keylime-base-7.3.0-13.el9_4.1.s390x.rpm SHA-256: e436c1fdf85d08ede37cb37fa9559aa0c94c095445660c34232ebc39ce33082b
keylime-registrar-7.3.0-13.el9_4.1.s390x.rpm SHA-256: ea9c565a614b8b42f93cb510e6500b8617037462725afbad79adcb74f40fff5a
keylime-selinux-7.3.0-13.el9_4.1.noarch.rpm SHA-256: e5b4d56d1aff185f3339f552c2600e3a944b05973ac8523ca26780a5f31041a1
keylime-tenant-7.3.0-13.el9_4.1.s390x.rpm SHA-256: 95e144bb4b3ed8614830991645b54854823d95488e3e087023dabac3ca33916d
keylime-verifier-7.3.0-13.el9_4.1.s390x.rpm SHA-256: 0688c387f69ee7c5302f71ac4c281b265b19957a26115d14647992ff9c4428fd
python3-keylime-7.3.0-13.el9_4.1.s390x.rpm SHA-256: 285eaedf9ab20cbc2a061f9a888d3137b3d432ef0bd3040ff59b19fb5cf2e635

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility