Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:2224 - Security Advisory
Issued:
2026-02-09
Updated:
2026-02-09

RHSA-2026:2224 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Critical: keylime security update

Type/Severity

Security Advisory: Critical

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for keylime is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution.

Security Fix(es):

  • keylime: Keylime: Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication (CVE-2026-1709)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2435514 - CVE-2026-1709 keylime: Keylime: Authentication bypass allows unauthorized administrative operations due to missing client-side TLS authentication

CVEs

  • CVE-2026-1709

References

  • https://access.redhat.com/security/updates/classification/#critical
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
keylime-7.12.1-11.el9_7.4.src.rpm SHA-256: b3c2cf862c072abe1635a15cc5d79788daec8710068486979a2caee665e66d6d
x86_64
keylime-7.12.1-11.el9_7.4.x86_64.rpm SHA-256: ad443caa766bce0c87f64a07f3bafd8e1009c3578b981e5a4c6134b7884de382
keylime-base-7.12.1-11.el9_7.4.x86_64.rpm SHA-256: 391d28dce62746e84fc57be705dc63f9a5e1e3d96b614896edd7f6d94be7db84
keylime-registrar-7.12.1-11.el9_7.4.x86_64.rpm SHA-256: 18690889760a38857830b29aecad5554bf71b06700097bced2a78b2534a5f6d2
keylime-selinux-7.12.1-11.el9_7.4.noarch.rpm SHA-256: 9059cb6642be785a852f9ca6e050fe088a9b29b0d25c50f3ae292c261a602189
keylime-tenant-7.12.1-11.el9_7.4.x86_64.rpm SHA-256: cc7d15a088d8c3b89c56b2cd13072962ff14fb21641e67f4249933d9d69776d4
keylime-verifier-7.12.1-11.el9_7.4.x86_64.rpm SHA-256: f87bb5b2cb52a13055fde0d3ae04733953f4de25716af5ed1dccd4cb5089bdb4
python3-keylime-7.12.1-11.el9_7.4.x86_64.rpm SHA-256: 80fb8108de6a0654fb334b38f31746c43837bce02966aa783245c17a87c0b941

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
keylime-7.12.1-11.el9_7.4.src.rpm SHA-256: b3c2cf862c072abe1635a15cc5d79788daec8710068486979a2caee665e66d6d
s390x
keylime-7.12.1-11.el9_7.4.s390x.rpm SHA-256: 7872ff9085485410945b4543a8b3840f80cd74cdaf014b389c72388dbd78adf8
keylime-base-7.12.1-11.el9_7.4.s390x.rpm SHA-256: 8d938190dbb42bcf3aabfec79cafdc1d9331fc360128c1b63ca7314949ca82b2
keylime-registrar-7.12.1-11.el9_7.4.s390x.rpm SHA-256: d43c66e54d2a8fc0123499235307d1fcd16d237edebd68028b52ecce79adc655
keylime-selinux-7.12.1-11.el9_7.4.noarch.rpm SHA-256: 9059cb6642be785a852f9ca6e050fe088a9b29b0d25c50f3ae292c261a602189
keylime-tenant-7.12.1-11.el9_7.4.s390x.rpm SHA-256: 5200142e94be053a61a5e6d80eed5015849c3cf6ed95dbef42de6d3e8573030c
keylime-verifier-7.12.1-11.el9_7.4.s390x.rpm SHA-256: 89f2463a54e3b65e97860e6a69a3e4c5a6071a968c1b771c42632017f3e57f50
python3-keylime-7.12.1-11.el9_7.4.s390x.rpm SHA-256: b874a5bf9dc03fdaf0fdcf9eed080b6820ce36207b27994704bd5725a619182a

Red Hat Enterprise Linux for Power, little endian 9

SRPM
keylime-7.12.1-11.el9_7.4.src.rpm SHA-256: b3c2cf862c072abe1635a15cc5d79788daec8710068486979a2caee665e66d6d
ppc64le
keylime-7.12.1-11.el9_7.4.ppc64le.rpm SHA-256: 868c18f61ce75183b2ce4024e5d678705c5bae902a536d03cd1dd473be7786db
keylime-base-7.12.1-11.el9_7.4.ppc64le.rpm SHA-256: 5842fa96133c2a262356f6d0261b8efaca66de3015b7062d4d32d695f614d6b1
keylime-registrar-7.12.1-11.el9_7.4.ppc64le.rpm SHA-256: aec71b3378401c166d5ce0076dd23d844163f37ead5925e93322e4a447ead2dd
keylime-selinux-7.12.1-11.el9_7.4.noarch.rpm SHA-256: 9059cb6642be785a852f9ca6e050fe088a9b29b0d25c50f3ae292c261a602189
keylime-tenant-7.12.1-11.el9_7.4.ppc64le.rpm SHA-256: 6dd10f81ed9ad8ad139985d045484e33595d00ed10cd7e451d2a6a34f2fd758f
keylime-verifier-7.12.1-11.el9_7.4.ppc64le.rpm SHA-256: b04c014ccc950ed1cdc996e4608a1e566b101e964e0a69087f652cd9986cb7d0
python3-keylime-7.12.1-11.el9_7.4.ppc64le.rpm SHA-256: 1c97fe8abd634d5e4132e0e1b0c844e2f9093a04df6f6b05426f73516f19db4b

Red Hat Enterprise Linux for ARM 64 9

SRPM
keylime-7.12.1-11.el9_7.4.src.rpm SHA-256: b3c2cf862c072abe1635a15cc5d79788daec8710068486979a2caee665e66d6d
aarch64
keylime-7.12.1-11.el9_7.4.aarch64.rpm SHA-256: 69fc08ee70afe950d6487afe5eb551af4ea6a36dbd2e4fa339dde1e72748a3df
keylime-base-7.12.1-11.el9_7.4.aarch64.rpm SHA-256: 534bcb5b1c4e9a0d973f34b318f85780062e296d42d99300dcfd8796e3bafe83
keylime-registrar-7.12.1-11.el9_7.4.aarch64.rpm SHA-256: 422972ecec9ee5bb71184502def31264aae5ee6d1c7b1c175bf938db887454a5
keylime-selinux-7.12.1-11.el9_7.4.noarch.rpm SHA-256: 9059cb6642be785a852f9ca6e050fe088a9b29b0d25c50f3ae292c261a602189
keylime-tenant-7.12.1-11.el9_7.4.aarch64.rpm SHA-256: 21ea0dc553e598db6d0f75fe9c93d8f35ac7c31406d0bb0982fa7e40052eb909
keylime-verifier-7.12.1-11.el9_7.4.aarch64.rpm SHA-256: e45063da2b7f1c29641938943c82841c76c32d9ddcda9ca0fe11a0162fc04109
python3-keylime-7.12.1-11.el9_7.4.aarch64.rpm SHA-256: d88746c194220704e33a1c77992307225572f3fa4e9e35ad88eb675e56b3775b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility