Ubuntu Security Update USN-6796-1: TPM2 Software Stack vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,872
Reaction score
74
Credits
-1,257
Fergus Dall discovered that TPM2 Software Stack did not properly handle layer arrays. An attacker could possibly use this issue to cause TPM2 Software Stack to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-22745) Jurgen Repp and Andreas Fuchs discovered that TPM2 Software Stack did not validate the quote data after deserialization. An attacker could generate an arbitrary quote and cause TPM2 Software Stack to have unknown behavior. (CVE-2024-29040)

Continue reading...
 


Follow Linux.org

Members online


Top