CVE-2024-29040

Name
CVE-2024-29040
Description
This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This issue has been patched in version 4.1.0.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/tpm2-software/tpm2-tss/releases/tag/4.1.0
CONFIRM https://github.com/tpm2-software/tpm2-tss/security/advisories/GHSA-837m-jw3m-h9p6
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFR7SVEWCOXORHPCLLGXEMHFMIGG2MFE/
af854a3a-2127-422b-91ae-364da2661108 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GI4JFEZBKQQUPJ4RWK6IHEWXAFCEJDPI/

Match rules

CPE URI Source package Min version Max version
tpm2-tss >= 0 < 4.1.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
tpm2-tss edge-community 4.1.1-r0 Alexander Sack <asac@pantacor.com> fixed
tpm2-tss 3.22-community 4.1.1-r0 None fixed
tpm2-tss 3.21-community 4.1.1-r0 None fixed
tpm2-tss 3.20-community 4.1.1-r0 Alexander Sack <asac@pantacor.com> fixed
tpm2-tss 3.19-community 4.0.2-r0 Alexander Sack <asac@pantacor.com> fixed