Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0429 - Security Advisory
Issued:
2026-01-12
Updated:
2026-01-12

RHSA-2026:0429 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: keylime security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for keylime is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution.

Security Fix(es):

  • keylime: Keylime: Registrar allows identity takeover via duplicate UUID registration (CVE-2025-13609)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64

Fixes

  • BZ - 2416761 - CVE-2025-13609 keylime: Keylime: Registrar allows identity takeover via duplicate UUID registration

CVEs

  • CVE-2025-13609

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0

SRPM
keylime-7.12.1-2.el10_0.4.src.rpm SHA-256: b8e4560e8bc9dcbe50c9079f77eaf17906b7acc4adeeb006f425283a08cd8736
x86_64
keylime-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 2c420b920b5e0a7a6973e6659cfa6ffb4b05e0b7dcc3117081e4a4c1759b581b
keylime-base-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 3aedd31c161976a59d7a79942ae422de00b27023b9b4eb6399a1e28c4f020a80
keylime-registrar-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 80155afe0ac0bc7d47a4c0adcfe3b2e6adf443fc0fdd08fecac892d6eb7577e1
keylime-selinux-7.12.1-2.el10_0.4.noarch.rpm SHA-256: 0d576f0cd8509e3092b2ddb25425689d0936b3b0f62ca3fd772a0adbd3dee5e8
keylime-tenant-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 4013f7f808778fa86cefefcf7eb7b0419806e9cf748f57428e21c1b4eb551c0a
keylime-tools-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 611ffec4699ca221f959596ea1d6b163af03c13bcee129e2281c13889f6b2853
keylime-verifier-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 40fc4ec3c2b28511e7455d2587801d18a6543bffac2c4baf621e6cbad20b0f46
python3-keylime-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 6c789bfe0db83af1e416a2c6d49a0c8d1a181e555fed48e210847b1f2e9f26df

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0

SRPM
keylime-7.12.1-2.el10_0.4.src.rpm SHA-256: b8e4560e8bc9dcbe50c9079f77eaf17906b7acc4adeeb006f425283a08cd8736
s390x
keylime-7.12.1-2.el10_0.4.s390x.rpm SHA-256: 3a89ca40d89ecf9f531cd1a0595c02acc063bcaf03f4ca30fcbc06009d6bf57d
keylime-base-7.12.1-2.el10_0.4.s390x.rpm SHA-256: a020361ea40168a476c05acc51cd4813b7e6dbadca359eae3b828641762ba21b
keylime-registrar-7.12.1-2.el10_0.4.s390x.rpm SHA-256: ded08c5afb9d1e2f7527a8617fc5a19418ae271cc408a04eca2805e4d90dfe4a
keylime-selinux-7.12.1-2.el10_0.4.noarch.rpm SHA-256: 0d576f0cd8509e3092b2ddb25425689d0936b3b0f62ca3fd772a0adbd3dee5e8
keylime-tenant-7.12.1-2.el10_0.4.s390x.rpm SHA-256: c15ee033e6ce379ddc532c45417dd11a0f71aa67bfcaf0e769b3172de4e0bebf
keylime-tools-7.12.1-2.el10_0.4.s390x.rpm SHA-256: 6620b1682cbed16c99d603c1d3a3168d320a6a5d6a76770d527cc73f09b6c037
keylime-verifier-7.12.1-2.el10_0.4.s390x.rpm SHA-256: a3a147baa4f5d37f3b62ce6b5a134d5b36663e64d395c5cdd922bf7ac6f6446f
python3-keylime-7.12.1-2.el10_0.4.s390x.rpm SHA-256: d37932ccfcb0f6e4582f7037e2c7dbe36fcfc4cb3ace73dc79f82fd5e9302160

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0

SRPM
keylime-7.12.1-2.el10_0.4.src.rpm SHA-256: b8e4560e8bc9dcbe50c9079f77eaf17906b7acc4adeeb006f425283a08cd8736
ppc64le
keylime-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 7d8eb1ce7820642299663b16b538270beb85b71ff407a9c2cf2eab7556dd1c26
keylime-base-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: dc6d8e6afd4b745f571e37be867841c6d34ffb11170844c716823d681fec3bc8
keylime-registrar-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: bf01a4953996596cdcecb0d502d67d37e73ba44966a45596257be9de09362841
keylime-selinux-7.12.1-2.el10_0.4.noarch.rpm SHA-256: 0d576f0cd8509e3092b2ddb25425689d0936b3b0f62ca3fd772a0adbd3dee5e8
keylime-tenant-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 4c9a1412f91ed42f9bea6675e904f47e48f995bc905bc07b7c04107c8f34acab
keylime-tools-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 18e251a680882d9d1efc413482defda679a7736bc6ef0a9942cc69f2df4cce82
keylime-verifier-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 7f3aae766627e74b041518fbae18ceeb2a5f54620c8d06634479d7302347e478
python3-keylime-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 4951a6777c843cfef990673a8c250a5d446653d98f09b1c948d7e6258d630453

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0

SRPM
keylime-7.12.1-2.el10_0.4.src.rpm SHA-256: b8e4560e8bc9dcbe50c9079f77eaf17906b7acc4adeeb006f425283a08cd8736
aarch64
keylime-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: e37b3ca43e975b4abcc0a6c44cc4f86476620f6fcbafb1fe6965a3cb65fe3dda
keylime-base-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: 9d1cec46ccbd454af5bd73b9fde139c26478fa5a5b1eafe8a02bcc6642b5c140
keylime-registrar-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: d54dc1694e169aeb88184814eb7a5a3254a4843b3606581f2cde0dcd6919e6c8
keylime-selinux-7.12.1-2.el10_0.4.noarch.rpm SHA-256: 0d576f0cd8509e3092b2ddb25425689d0936b3b0f62ca3fd772a0adbd3dee5e8
keylime-tenant-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: e389af3fa6c3e30ae042fb572a04071e2ab75823987260ee9babc67d7825dded
keylime-tools-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: 09277d6bedb383d74f4c55067c55aa08cbca6ce6526f269a5233f3d4b5255481
keylime-verifier-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: 8743c99346bccbf2e260a353cb533d9ea48ccab4f4c1c60dd410d294ec298c4c
python3-keylime-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: 123cdfba01a8ad496b9cd9825b74425dd6335aba8a6b4d064306ee1c99783604

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0

SRPM
keylime-7.12.1-2.el10_0.4.src.rpm SHA-256: b8e4560e8bc9dcbe50c9079f77eaf17906b7acc4adeeb006f425283a08cd8736
aarch64
keylime-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: e37b3ca43e975b4abcc0a6c44cc4f86476620f6fcbafb1fe6965a3cb65fe3dda
keylime-base-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: 9d1cec46ccbd454af5bd73b9fde139c26478fa5a5b1eafe8a02bcc6642b5c140
keylime-registrar-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: d54dc1694e169aeb88184814eb7a5a3254a4843b3606581f2cde0dcd6919e6c8
keylime-selinux-7.12.1-2.el10_0.4.noarch.rpm SHA-256: 0d576f0cd8509e3092b2ddb25425689d0936b3b0f62ca3fd772a0adbd3dee5e8
keylime-tenant-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: e389af3fa6c3e30ae042fb572a04071e2ab75823987260ee9babc67d7825dded
keylime-tools-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: 09277d6bedb383d74f4c55067c55aa08cbca6ce6526f269a5233f3d4b5255481
keylime-verifier-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: 8743c99346bccbf2e260a353cb533d9ea48ccab4f4c1c60dd410d294ec298c4c
python3-keylime-7.12.1-2.el10_0.4.aarch64.rpm SHA-256: 123cdfba01a8ad496b9cd9825b74425dd6335aba8a6b4d064306ee1c99783604

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0

SRPM
keylime-7.12.1-2.el10_0.4.src.rpm SHA-256: b8e4560e8bc9dcbe50c9079f77eaf17906b7acc4adeeb006f425283a08cd8736
s390x
keylime-7.12.1-2.el10_0.4.s390x.rpm SHA-256: 3a89ca40d89ecf9f531cd1a0595c02acc063bcaf03f4ca30fcbc06009d6bf57d
keylime-base-7.12.1-2.el10_0.4.s390x.rpm SHA-256: a020361ea40168a476c05acc51cd4813b7e6dbadca359eae3b828641762ba21b
keylime-registrar-7.12.1-2.el10_0.4.s390x.rpm SHA-256: ded08c5afb9d1e2f7527a8617fc5a19418ae271cc408a04eca2805e4d90dfe4a
keylime-selinux-7.12.1-2.el10_0.4.noarch.rpm SHA-256: 0d576f0cd8509e3092b2ddb25425689d0936b3b0f62ca3fd772a0adbd3dee5e8
keylime-tenant-7.12.1-2.el10_0.4.s390x.rpm SHA-256: c15ee033e6ce379ddc532c45417dd11a0f71aa67bfcaf0e769b3172de4e0bebf
keylime-tools-7.12.1-2.el10_0.4.s390x.rpm SHA-256: 6620b1682cbed16c99d603c1d3a3168d320a6a5d6a76770d527cc73f09b6c037
keylime-verifier-7.12.1-2.el10_0.4.s390x.rpm SHA-256: a3a147baa4f5d37f3b62ce6b5a134d5b36663e64d395c5cdd922bf7ac6f6446f
python3-keylime-7.12.1-2.el10_0.4.s390x.rpm SHA-256: d37932ccfcb0f6e4582f7037e2c7dbe36fcfc4cb3ace73dc79f82fd5e9302160

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0

SRPM
keylime-7.12.1-2.el10_0.4.src.rpm SHA-256: b8e4560e8bc9dcbe50c9079f77eaf17906b7acc4adeeb006f425283a08cd8736
ppc64le
keylime-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 7d8eb1ce7820642299663b16b538270beb85b71ff407a9c2cf2eab7556dd1c26
keylime-base-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: dc6d8e6afd4b745f571e37be867841c6d34ffb11170844c716823d681fec3bc8
keylime-registrar-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: bf01a4953996596cdcecb0d502d67d37e73ba44966a45596257be9de09362841
keylime-selinux-7.12.1-2.el10_0.4.noarch.rpm SHA-256: 0d576f0cd8509e3092b2ddb25425689d0936b3b0f62ca3fd772a0adbd3dee5e8
keylime-tenant-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 4c9a1412f91ed42f9bea6675e904f47e48f995bc905bc07b7c04107c8f34acab
keylime-tools-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 18e251a680882d9d1efc413482defda679a7736bc6ef0a9942cc69f2df4cce82
keylime-verifier-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 7f3aae766627e74b041518fbae18ceeb2a5f54620c8d06634479d7302347e478
python3-keylime-7.12.1-2.el10_0.4.ppc64le.rpm SHA-256: 4951a6777c843cfef990673a8c250a5d446653d98f09b1c948d7e6258d630453

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0

SRPM
keylime-7.12.1-2.el10_0.4.src.rpm SHA-256: b8e4560e8bc9dcbe50c9079f77eaf17906b7acc4adeeb006f425283a08cd8736
x86_64
keylime-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 2c420b920b5e0a7a6973e6659cfa6ffb4b05e0b7dcc3117081e4a4c1759b581b
keylime-base-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 3aedd31c161976a59d7a79942ae422de00b27023b9b4eb6399a1e28c4f020a80
keylime-registrar-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 80155afe0ac0bc7d47a4c0adcfe3b2e6adf443fc0fdd08fecac892d6eb7577e1
keylime-selinux-7.12.1-2.el10_0.4.noarch.rpm SHA-256: 0d576f0cd8509e3092b2ddb25425689d0936b3b0f62ca3fd772a0adbd3dee5e8
keylime-tenant-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 4013f7f808778fa86cefefcf7eb7b0419806e9cf748f57428e21c1b4eb551c0a
keylime-tools-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 611ffec4699ca221f959596ea1d6b163af03c13bcee129e2281c13889f6b2853
keylime-verifier-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 40fc4ec3c2b28511e7455d2587801d18a6543bffac2c4baf621e6cbad20b0f46
python3-keylime-7.12.1-2.el10_0.4.x86_64.rpm SHA-256: 6c789bfe0db83af1e416a2c6d49a0c8d1a181e555fed48e210847b1f2e9f26df

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility