Database/Firmware, BMC & network fabric

Keylime verifier: hardcoded TPM quote nonce lets a compromised node replay stockpiled attestations
Impact
Keylime's job is to tell you that a node's boot and runtime measurements still match what you expect; a quote is only trustworthy because the verifier supplies a fresh random nonce that the TPM signs. In the push model the verifier uses a hardcoded nonce instead, so an attacker who has root on an enrolled node can collect valid quotes while the node is still clean and replay them afterwards. Attestation then keeps reporting the node as healthy after it has been tampered with, which is exactly the failure mode remote attestation is bought to prevent. For an operator running confidential or attestation-gated GPU workloads, this means a compromised node can stay in the pool and keep receiving tenant work.
Who can reach it
A local attacker who already holds root on an enrolled monitored machine where the Keylime agent runs. Affects only push-model deployments; pull-model deployments are not affected per the advisory.
What to do
Apply the vendor package update (RHSA-2026:28582 for RHEL 9 and 10) and restart the Keylime verifier and agents - a service restart, not a node reboot. Until patched, prefer the pull model, and treat push-model attestation results from the exposure window as unproven rather than as evidence a node is clean.
References
Related entries
- Linux KVM - PV TLB shootdown leaks memory between guest processes: In a KVM guest with paravirtualised TLB enabled, oneCVE-2019-3016 · Linux KVM - PV TLB shootdown leaks memory between guest processesMedium
- APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500: Stored/reflectedCVE-2021-22810 · APC Network Management Card 2 (AP9630/AP9631/AP9635) in Smart-UPS, Symmetra and Galaxy 3500Medium
- Arista EOS (TerminAttr / OpenConfig telemetry transport): The streaming-telemetry agent can leak MACsec keys over theCVE-2021-28509 · Arista EOS (TerminAttr / OpenConfig telemetry transport)Medium
- IBM OpenBMC OP910 web UI (phosphor-webui lineage): Stored/reflected script injection in the BMC web interfaceCVE-2021-38961 · IBM OpenBMC OP910 web UI (phosphor-webui lineage)Medium
- Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): A protection mechanism in 3rd and 4th generationCVE-2023-22655 · Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure)Medium
- shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from bootingCVE-2023-40546 · shim (mok.c mirror_one_esl)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.