PatchSiren cyber security CVE debrief
CVE-2026-6420 Red Hat CVE debrief
CVE-2026-6420 is a medium-severity vulnerability in the Keylime verifier. An attacker with root access on an enrolled monitored machine can exploit this flaw to stockpile valid TPM quotes and replay them to evade detection. The verifier uses a hardcoded challenge nonce for TPM quote attestation instead of a cryptographically random value. This issue affects only the push model deployment. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 6.3, indicating a medium severity.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-06
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-05-06
- Advisory updated
- 2026-08-26
Who should care
Security teams responsible for Keylime deployments, particularly those using the push model, should be aware of this vulnerability. An attacker with root access on an enrolled monitored machine could exploit this flaw to evade detection. Therefore, defenders should assess their exposure and take necessary actions to mitigate this risk.
Technical summary
The Keylime verifier uses a hardcoded challenge nonce for Trusted Platform Module (TPM) quote attestation instead of a cryptographically random value. This allows an attacker with root access on an enrolled monitored machine to stockpile valid TPM quotes and replay them to evade detection after compromising the system. The vulnerability affects only the push model deployment of Keylime. The CVSS vector for this vulnerability is CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability in Keylime deployments, especially in environments where an attacker gaining root access is a concern. Given the medium severity and potential for exploitation, timely action is recommended.
Recommended defensive actions
- Assess Keylime deployment configurations and identify instances using the push model.
- Verify if the affected Keylime verifier is in use and prioritize patching.
- Implement compensating controls to monitor for suspicious TPM quote activity.
- Review and update incident response plans to account for potential exploitation.
- Consider enhancing monitoring and logging for Keylime verifier interactions.
Evidence notes
The CVE-2026-6420 record was obtained from the National Vulnerability Database (NVD) and provides details on the Keylime verifier vulnerability. The vulnerability allows an attacker with root access to exploit the hardcoded challenge nonce in TPM quote attestation. The CVSS score and vector provide additional context on the severity and characteristics of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6420 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6420
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6420 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6420
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:28582
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-6420
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.