tpm2-tools: fixed AES wrapping key in tpm2_import
Published Jun 4, 2021
5.9
MEDIUMCVSS 3.1
EPSS 1.33%
Description
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.
Affected products
- Vendor n/a Product Tpm2-Tools Defaultunknown
Affected
- tpm2-tools 5.1.1, tpm2-tools 4.3.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Tpm2-Tools | unknown | Affected
|
Configuration 1
- < 4.3.2
- ≥ 5.1 · < 5.1.1
Configuration 2
- 8.0
Configuration 3
- 33
- 34
No data.
Red Hat Enterprise Linux 8
tpm2-tools-0:4.1.1-5.el8
Fixed · RHSA-2021:4413
Red Hat Enterprise Linux 7
tpm2-tools
Not affected
Red Hat Enterprise Linux 9
tpm2-tools
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | tpm2-tools-0:4.1.1-5.el8 | Fixed | RHSA-2021:4413 |
| Red Hat Enterprise Linux 7 | tpm2-tools | Not affected | n/a |
| Red Hat Enterprise Linux 9 | tpm2-tools | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux 7 is not affected by this issue, as it ships an older version of `tpm2-tools` which does not include the tpm2_import tool.
References (7)
- https://access.redhat.com/security/cve/CVE-2021-3565 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1964427 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26875 Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ESY6HRYUKR5ZG2K5QAJQC5S6HMKZMFK7/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XK5M7I66PBXSN663TSLAZ3V6TWWFCV7C/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2021-3565
- https://www.cve.org/CVERecord?id=CVE-2021-3565
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-3565 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1964427 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26875 | Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ESY6HRYUKR5ZG2K5QAJQC5S6HMKZMFK7/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XK5M7I66PBXSN663TSLAZ3V6TWWFCV7C/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-3565 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-3565 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data