Critical Security Bypass in Fedora Keylime Affects Multiple Versions

Critical Security Bypass in Fedora Keylime Affects Multiple Versions

First seen 7 Jun 2026, 06:19 UTC Linuxsecurity 98% similarity 70.5

Article Content

Browse articles
ThreatCluster

Fedora has released a critical update for Keylime version 7.14.2 to address CVE-2026-6420, a security bypass vulnerability caused by a hardcoded TPM quote nonce. This flaw affects users of Fedora 43 and 44, potentially allowing unauthorized access to sensitive data. The vulnerability was published on May 6, 2026, and has been confirmed to impact the keylime-selinux policy. Users are advised to upgrade to the latest version (44.1.0) to mitigate risks. The update can be installed using the 'dnf' package manager. As of June 7, 2026, no active exploitation has been reported, but the severity of the vulnerability necessitates immediate attention from system administrators.

Key Points: • CVE-2026-6420 is a critical security bypass affecting Fedora Keylime versions. • The vulnerability is due to a hardcoded TPM quote nonce, allowing potential unauthorized access. • Users are urged to update to keylime-selinux policy version 44.1.0 immediately.

ThreatCluster AI

Timeline

2026-05-06
CVE-2026-6420 published
CVE-2026-6420 was published, detailing a security bypass in Keylime due to a hardcoded TPM quote nonce.
Linuxsecurity
2026-05-27
Keylime release v7.14.2 issued
Fedora released Keylime version 7.14.2, which includes a fix for CVE-2026-6420 and updates to the keylime-selinux policy.
Linuxsecurity
2026-06-07
Security advisory published
Fedora issued a security advisory urging users to upgrade to the latest keylime-selinux policy to address CVE-2026-6420.
Linuxsecurity

Community

Browse all →