Out-of-bounds read in swtpm
Published Feb 18, 2022
6.2
MEDIUMCVSS 3.1
EPSS 0.40%
Description
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.
Affected products
-
- Version < 0.5.3StatusaffectedConstraints-
- Version = 0.7.0StatusaffectedConstraints-
- Version >= 0.6.0, < 0.6.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Stefanberger | Swtpm | n/a |
|
Configuration 1
- < 0.5.3
- ≥ 0.6.0 · < 0.6.2
- 0.7.0
- 0.7.0
- 0.7.0
Configuration 2
- 8.0
Configuration 3
- 35
No data.
Red Hat Enterprise Linux 8
virt-devel:rhel-8070020220921004438.3b9f49c4
Fixed · RHSA-2022:7472
Red Hat Enterprise Linux 8
virt:rhel-8070020220921004438.3b9f49c4
Fixed · RHSA-2022:7472
Red Hat Enterprise Linux 9
swtpm-0:0.7.0-3.20211109gitb79fd91.el9
Fixed · RHSA-2022:8100
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.2/swtpm
Not affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:av/swtpm
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | virt-devel:rhel-8070020220921004438.3b9f49c4 | Fixed | RHSA-2022:7472 |
| Red Hat Enterprise Linux 8 | virt:rhel-8070020220921004438.3b9f49c4 | Fixed | RHSA-2022:7472 |
| Red Hat Enterprise Linux 9 | swtpm-0:0.7.0-3.20211109gitb79fd91.el9 | Fixed | RHSA-2022:8100 |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/swtpm | Not affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/swtpm | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
No possible workarounds. Users should upgrade to swtpm v0.5.3, v0.6.2 or v0.7.1.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-23645 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2056491 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28593 Advisory
- https://github.com/stefanberger/swtpm/commit/9f740868fc36761de27df3935513bdebf8852d19 x_refsource_MISCPatchThird Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.5.3 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.6.2 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.7.1 x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/stefanberger/swtpm/security/advisories/GHSA-2qgm-8xf4-3hqw x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WL735FW266GO4C2JX4CJBOIOB7R7AY5A/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2022-23645
- https://www.cve.org/CVERecord?id=CVE-2022-23645
Change history (0)
No recorded changes yet.