PT-2024-4042 · Unknown+6 · Tpm2 Software Stack+6
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TPM2 Software Stack versions prior to 4.1.0
Description
The issue is related to the TPM2 GENERATED VALUE() function in the TCG TPM2 TPM2 Software Stack implementation. It lacks a check to ensure the magic number in the attest matches the TPM2 GENERATED VALUE. This allows an attacker to generate arbitrary quote data that may not be detected by Fapi VerifyQuote. The verifier can receive a state that does not represent the actual state of the device under test, potentially granting malicious devices access to unauthorized data or services.
Recommendations
For versions prior to 4.1.0, update to version 4.1.0 to resolve the issue. As a temporary workaround, consider restricting access to the
TPMS ATTEST structure and the Fapi Quote and Fapi VerifyQuote functions to minimize the risk of exploitation. Avoid using arbitrary numbers in the TPM2 GENERATED magic field of the JSON structure until the issue is resolved.Exploit
Fix
DoS
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Red Os
Suse
Tpm2 Software Stack
Ubuntu