CVE-2025-13609Patch

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This action overwrites the legitimate agent's identity, enabling the attacker to impersonate the compromised agent and potentially bypass security controls.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-694

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-04); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-04: 1Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-20: 103-0403-20
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-041
Patch1
2026-03-201
Disclosure1
Full discourse2 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Keylime` users should be aware of CVE-2025-13609, a vulnerability allowing agent UUID recycling with different TPMs. This could impact attestation integrity. Monitor for updates. #Keylime #InfoSec #Cybersecurity https://www.pulsepatch.io/posts/cve-2025-13609-keylime-agent-uuid-reuse

    Post summary

    Keylime users are warned about CVE‑2025‑13609, a flaw that can recycle agent UUIDs across different TPMs, potentially undermining attestation integrity; users should monitor for updates.

    0000086
    1 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Keylime updates for Archlinux and Fedora fix critical CVE-2026-1709 and CVE-2025-13609. Update to keylime 7.14.1 and keylime-agent-rust 0.2.9 to mitigate exposure. https://threatcluster.io/cluster/keylime-updates-address-critical-vulnerabilities-in-archlinu-96c6862f

    Post summary

    Keylime releases updates for Archlinux and Fedora to address critical CVE-2026-1709 and CVE-2025-13609, recommending users upgrade to keylime 7.14.1 and keylime-agent-rust 0.2.9.

    0000088
    89 followersView on X

Explore more