libtpms: stack corruption bug in RSA decryption
Published Jun 3, 2021
6.2
MEDIUMCVSS 3.1
EPSS 0.26%
Description
A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.
Affected products
- Vendor n/a Product Libtpms Defaultunknown
Affected
- libtpms 0.7.2, libtpms 0.8.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Libtpms | unknown | Affected
|
Configuration 1
- < 0.7.2
- ≥ 0.7.3 · < 0.8.0
Configuration 2
- 8.0
No data.
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.2/libtpms
Will not fix
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.3/libtpms
Not affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:av/libtpms
Not affected
Red Hat Enterprise Linux 9
libtpms
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/libtpms | Will not fix | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.3/libtpms | Not affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/libtpms | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libtpms | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2021-3569 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1964358 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26879 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3569
- https://www.cve.org/CVERecord?id=CVE-2021-3569
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2021-3569 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1964358 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-26879 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-3569 | ||
| https://www.cve.org/CVERecord?id=CVE-2021-3569 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data