GPU VulnDB

Database/Firmware, BMC & network fabric

Keylime verifier: hardcoded TPM quote nonce lets a compromised node replay stockpiled attestations

CVE-2026-6420Firmware, BMC & network fabriccurated

Impact

Keylime's job is to tell you that a node's boot and runtime measurements still match what you expect; a quote is only trustworthy because the verifier supplies a fresh random nonce that the TPM signs. In the push model the verifier uses a hardcoded nonce instead, so an attacker who has root on an enrolled node can collect valid quotes while the node is still clean and replay them afterwards. Attestation then keeps reporting the node as healthy after it has been tampered with, which is exactly the failure mode remote attestation is bought to prevent. For an operator running confidential or attestation-gated GPU workloads, this means a compromised node can stay in the pool and keep receiving tenant work.

Who can reach it

A local attacker who already holds root on an enrolled monitored machine where the Keylime agent runs. Affects only push-model deployments; pull-model deployments are not affected per the advisory.

What to do

Apply the vendor package update (RHSA-2026:28582 for RHEL 9 and 10) and restart the Keylime verifier and agents - a service restart, not a node reboot. Until patched, prefer the pull model, and treat push-model attestation results from the exposure window as unproven rather than as evidence a node is clean.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.