tpm2-tools-5.2-4.el9

エラータID: AXSA:2024-9175:01

Release date: 
Thursday, December 12, 2024 - 09:24
Subject: 
tpm2-tools-5.2-4.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Low
Description: 

The tpm2-tools packages add a set of utilities for management and utilization of Trusted Platform Module (TPM) 2.0 devices from user space.

Security Fix(es):

* tpm2-tools: arbitrary quote data may go undetected by tpm2_checkquote (CVE-2024-29038)
* tpm2-tools: pcr selection value is not compared with the attest (CVE-2024-29039)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the MIRACLE LINUX 9.5 Release Notes linked from the References section.

CVE-2024-29038
tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.
CVE-2024-29039
tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in the PCR input file. As a result, digest values are incorrectly mapped to PCR slots and banks, providing a misleading picture of the TPM state. This issue has been patched in version 5.7.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. tpm2-tools-5.2-4.el9.src.rpm
    MD5: fc4fbf74228ac1fa79ed60dc5fafff72
    SHA-256: 0f65297afa7cd811043a2c550523b8fd7cf17a3f01c830de22d837c95e5992a5
    Size: 1.17 MB

Asianux Server 9 for x86_64
  1. tpm2-tools-5.2-4.el9.x86_64.rpm
    MD5: 2a8d06475a55c64e9c8cab9536f6f799
    SHA-256: 2aed88c93fe50f69fd6fa6413476a56d3ab6f7c67a4eae35283a19f52118392d
    Size: 776.60 kB