Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for keylime Announcement ID: SUSE-SU-2026:22326-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1264265 Cross-References: * CVE-2026-6420 CVSS scores: * CVE-2026-6420 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-6420 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2026-6420 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for keylime fixes the following issue * CVE-2026-6420: use of hardcoded challenge nonce for TPM quote attestation allows for security bypass (bsc#1264265). Changes for keylime: * Update to version 7.14.2. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1037=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1037=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * keylime-tenant-7.14.2-160000.1.1 * keylime-firewalld-7.14.2-160000.1.1 * keylime-tpm_cert_store-7.14.2-160000.1.1 * keylime-config-7.14.2-160000.1.1 * keylime-verifier-7.14.2-160000.1.1 * keylime-logrotate-7.14.2-160000.1.1 * keylime-registrar-7.14.2-160000.1.1 * python313-keylime-7.14.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * keylime-tenant-7.14.2-160000.1.1 * keylime-firewalld-7.14.2-160000.1.1 * keylime-tpm_cert_store-7.14.2-160000.1.1 * keylime-config-7.14.2-160000.1.1 *keylime-verifier-7.14.2-160000.1.1 * keylime-logrotate-7.14.2-160000.1.1 * keylime-registrar-7.14.2-160000.1.1 * python313-keylime-7.14.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6420.html * https://bugzilla.suse.com/show_bug.cgi?id=1264265 . Keylime security update on SUSE addresses a security bypass issue with a moderate rating. Install now for enhanced protection.. SUSE Keylime Security Update Moderate Security Bypass Patch. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for keylime ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21025-1 Rating: moderate References: * bsc#1264265 Cross-References: * CVE-2026-6420 CVSS scores: * CVE-2026-6420 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2026-6420 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for keylime fixes the following issue - CVE-2026-6420: use of hardcoded challenge nonce for TPM quote attestation allows for security bypass (bsc#1264265). Changes for keylime: - Update to version 7.14.2. Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1037=1 Package List: - openSUSE Leap 16.0: keylime-config-7.14.2-160000.1.1 keylime-firewalld-7.14.2-160000.1.1 keylime-logrotate-7.14.2-160000.1.1 keylime-registrar-7.14.2-160000.1.1 keylime-tenant-7.14.2-160000.1.1 keylime-tpm_cert_store-7.14.2-160000.1.1 keylime-verifier-7.14.2-160000.1.1 python313-keylime-7.14.2-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-6420.html . Get essential updates for openSUSE keylime including a fix for a vulnerability and a bug. Stay secure with this essential patch.. openSUSE keylime update,bypass security fix,moderate vulnerability,TPM security fix. . Severity: moderate. LinuxSecurity.com Team
Moderate: keylime security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28582", "synopsis": "Moderate: keylime security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for keylime.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution.\n\nSecurity Fix(es):\n\n* keylime: Keylime: Security bypass due to hardcoded TPM quote nonce (CVE-2026-6420)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2458889", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2458889", "description": ""}], "cves": [{"name": "CVE-2026-6420", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-6420", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L", "cvss3BaseScore": "6.3", "cwe": "CWE-1241"}], "references": [], "publishedAt": "2026-06-25T12:05:27.708216Z", "rpms": {"Rocky Linux 10": {"nvras": ["keylime-base-0:7.14.1-5.el10_2.1.s390x.rpm", "python3-keylime-0:7.14.1-5.el10_2.1.ppc64le.rpm", "keylime-tools-0:7.14.1-5.el10_2.1.x86_64.rpm", "keylime-base-0:7.14.1-5.el10_2.1.aarch64.rpm", "keylime-0:7.14.1-5.el10_2.1.x86_64.rpm", "keylime-0:7.14.1-5.el10_2.1.ppc64le.rpm", "keylime-verifier-0:7.14.1-5.el10_2.1.aarch64.rpm", "keylime-registrar-0:7.14.1-5.el10_2.1.ppc64le.rpm", "keylime-0:7.14.1-5.el10_2.1.src.rpm", "python3-keylime-0:7.14.1-5.el10_2.1.s390x.rpm", "keylime-tools-0:7.14.1-5.el10_2.1.aarch64.rpm", "keylime-tools-0:7.14.1-5.el10_2.1.ppc64le.rpm", "keylime-base-0:7.14.1-5.el10_2.1.x86_64.rpm","keylime-registrar-0:7.14.1-5.el10_2.1.aarch64.rpm", "keylime-verifier-0:7.14.1-5.el10_2.1.x86_64.rpm", "keylime-0:7.14.1-5.el10_2.1.s390x.rpm", "python3-keylime-0:7.14.1-5.el10_2.1.x86_64.rpm", "keylime-tools-0:7.14.1-5.el10_2.1.s390x.rpm", "keylime-verifier-0:7.14.1-5.el10_2.1.s390x.rpm", "keylime-0:7.14.1-5.el10_2.1.aarch64.rpm", "keylime-registrar-0:7.14.1-5.el10_2.1.x86_64.rpm", "keylime-tenant-0:7.14.1-5.el10_2.1.aarch64.rpm", "keylime-base-0:7.14.1-5.el10_2.1.ppc64le.rpm", "keylime-registrar-0:7.14.1-5.el10_2.1.s390x.rpm", "keylime-tenant-0:7.14.1-5.el10_2.1.ppc64le.rpm", "keylime-tenant-0:7.14.1-5.el10_2.1.x86_64.rpm", "keylime-selinux-0:7.14.1-5.el10_2.1.noarch.rpm", "keylime-tenant-0:7.14.1-5.el10_2.1.s390x.rpm", "python3-keylime-0:7.14.1-5.el10_2.1.aarch64.rpm", "keylime-verifier-0:7.14.1-5.el10_2.1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Keylime security update for Rocky Linux addresses a moderate security bypass issue. Update recommended for all users.. Rocky Linux Keylime Update Security Bypass CVE-2026-6420. . Severity: moderate. LinuxSecurity.com Team
Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-513c495139 2026-06-07 01:06:43.462201+00:00 -------------------------------------------------------------------------------- Name : keylime Product : Fedora 43 Version : 7.14.2 Release : 1.fc43 URL : https://github.com/keylime/keylime Summary : Open source TPM software for Bootstrapping and Maintaining Trust Description : Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution. -------------------------------------------------------------------------------- Update Information: Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Anderson Toshiyuki Sasaki - 7.14.2-1 - Updating for Keylime release v7.14.2 - This includes the fix for CVE-2026-6420. - Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2467277 - keylime-7.14.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467277 [ 2 ] Bug #2467584 - CVE-2026-6420 keylime: Keylime: Security bypass due to hardcoded TPM quote nonce [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2467584 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-513c495139' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9064cdf8ef 2026-06-07 00:55:32.282462+00:00 -------------------------------------------------------------------------------- Name : keylime Product : Fedora 44 Version : 7.14.2 Release : 1.fc44 URL : https://github.com/keylime/keylime Summary : Open source TPM software for Bootstrapping and Maintaining Trust Description : Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution. -------------------------------------------------------------------------------- Update Information: Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Anderson Toshiyuki Sasaki - 7.14.2-1 - Updating for Keylime release v7.14.2 - This includes the fix for CVE-2026-6420. - Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2467277 - keylime-7.14.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467277 [ 2 ] Bug #2467584 - CVE-2026-6420 keylime: Keylime: Security bypass due to hardcoded TPM quote nonce [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2467584 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9064cdf8ef' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-513c495139 2026-06-07 01:06:43.462201+00:00 -------------------------------------------------------------------------------- Name : keylime Product : Fedora 43 Version : 7.14.2 Release : 1.fc43 URL : https://github.com/keylime/keylime Summary : Open source TPM software for Bootstrapping and Maintaining Trust Description : Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution. -------------------------------------------------------------------------------- Update Information: Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Anderson Toshiyuki Sasaki - 7.14.2-1 - Updating for Keylime release v7.14.2 - This includes the fix for CVE-2026-6420. - Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2467277 - keylime-7.14.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467277 [ 2 ] Bug #2467584 - CVE-2026-6420 keylime: Keylime: Security bypass due to hardcoded TPM quote nonce [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2467584 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-513c495139' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9064cdf8ef 2026-06-07 00:55:32.282462+00:00 -------------------------------------------------------------------------------- Name : keylime Product : Fedora 44 Version : 7.14.2 Release : 1.fc44 URL : https://github.com/keylime/keylime Summary : Open source TPM software for Bootstrapping and Maintaining Trust Description : Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution. -------------------------------------------------------------------------------- Update Information: Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Anderson Toshiyuki Sasaki - 7.14.2-1 - Updating for Keylime release v7.14.2 - This includes the fix for CVE-2026-6420. - Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2467277 - keylime-7.14.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467277 [ 2 ] Bug #2467584 - CVE-2026-6420 keylime: Keylime: Security bypass due to hardcoded TPM quote nonce [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2467584 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9064cdf8ef' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild with version 0.10.79 of the openssl crate which includes fixes for the following security issues: CVE-2026-41676 / GHSA-pqf5-4pqq-29f5 CVE-2026-41677 / GHSA-xmgf-hq76-4vx2 CVE-2026-41678 / GHSA-8c75-8mhr-p7r9. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9002354692 2026-05-19 16:18:59.081704+00:00 -------------------------------------------------------------------------------- Name : keylime-agent-rust Product : Fedora 44 Version : 0.2.9 Release : 2.fc44 URL : https://github.com/keylime/rust-keylime/ Summary : The Keylime agent Description : The Keylime agent -------------------------------------------------------------------------------- Update Information: Rebuild with version 0.10.79 of the openssl crate which includes fixes for the following security issues: CVE-2026-41676 / GHSA-pqf5-4pqq-29f5 CVE-2026-41677 / GHSA-xmgf-hq76-4vx2 CVE-2026-41678 / GHSA-8c75-8mhr-p7r9 CVE-2026-41681 / GHSA-ghm9-cr32-g9qj CVE-2026-41898 / GHSA-hppc-g8h3-xhp3 CVE-2026-42327 / GHSA-xp3w-r5p5-63rr CVE-2026-44662 / GHSA-xv59-967r-8726 -------------------------------------------------------------------------------- ChangeLog: * Mon May 11 2026 Fabio Valentini - 0.2.9-2 - Rebuild for rust-openssl CVE-2026-{41676,41677,41678,41681,41898,42327,44662} -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9002354692' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.