TPM2.0 vulnerable to out-of-bounds write
Published Feb 28, 2023
7.8
HIGHCVSS 3.1
EPSS 1.29%
Description
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.
Affected products
-
- Version 1.19StatusaffectedConstraints-
- Version 1.38StatusaffectedConstraints-
- Version 1.59StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Trusted Computing Group | TPM2.0 | n/a |
|
Configuration 1
- 2.0
- 2.0
- 2.0
Configuration 2
- < 10.0.10240.19805
- < 10.0.14393.5786
- < 10.0.17763.4131
- < 10.0.19042.2728
- < 10.0.19044.2728
- < 10.0.19045.2728
- < 10.0.22000.1696
- < 10.0.22621.1413
- < 10.0.14393.5786
- < 10.0.17763.4131
- < 10.0.20348.1607
No data.
Red Hat Enterprise Linux 8.6 Extended Update Support
virt-devel:rhel-8060020230403063348.ad008a3a
Fixed · RHSA-2023:1833
Red Hat Enterprise Linux 8.6 Extended Update Support
virt:rhel-8060020230403063348.ad008a3a
Fixed · RHSA-2023:1833
Red Hat Enterprise Linux 9
libtpms-0:0.9.1-3.20211126git1ff6fe1f43.el9_2
Fixed · RHSA-2023:2453
Red Hat Enterprise Linux 8
virt:rhel/libtpms
Affected
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.2/libtpms
Will not fix
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.3/libtpms
Will not fix
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:av/libtpms
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8.6 Extended Update Support | virt-devel:rhel-8060020230403063348.ad008a3a | Fixed | RHSA-2023:1833 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | virt:rhel-8060020230403063348.ad008a3a | Fixed | RHSA-2023:1833 |
| Red Hat Enterprise Linux 9 | libtpms-0:0.9.1-3.20211126git1ff6fe1f43.el9_2 | Fixed | RHSA-2023:2453 |
| Red Hat Enterprise Linux 8 | virt:rhel/libtpms | Affected | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.2/libtpms | Will not fix | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.3/libtpms | Will not fix | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:av/libtpms | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-1017 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2149416 Issue Tracking
- https://kb.cert.org/vuls/id/782720 Third Party AdvisoryUS Government Resource
- https://nvd.nist.gov/vuln/detail/CVE-2023-1017
- https://trustedcomputinggroup.org/about/security/ Vendor Advisory
- https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT0007-Advisory-FINAL.pdf Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-1017
- https://www.kb.cert.org/vuls/id/782720
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-1017 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2149416 | Issue Tracking | |
| https://kb.cert.org/vuls/id/782720 | Third Party AdvisoryUS Government Resource | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-1017 | ||
| https://trustedcomputinggroup.org/about/security/ | Vendor Advisory | |
| https://trustedcomputinggroup.org/wp-content/uploads/TCGVRT0007-Advisory-FINAL.pdf | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2023-1017 | ||
| https://www.kb.cert.org/vuls/id/782720 |
Change history (0)
No recorded changes yet.