CVE-2021-3623
Summary
| CVE | CVE-2021-3623 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-02 23:15:00 UTC |
| Updated | 2023-11-07 03:38:00 UTC |
| Description | A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: libtpms-0.8.4-1.20210624gita594c4692a.fc34.1 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| tpm2: Add maxSize parameter to TPM2B_Marshal for sanity checks · stefanberger/libtpms@7981d9a · GitHub |
MISC |
github.com |
|
| 1976806 – (CVE-2021-3623) CVE-2021-3623 libtpms: out-of-bounds access when trying to resume the state of the vTPM |
MISC |
bugzilla.redhat.com |
|
| tpm2: Restore original value if unmarsalled value was illegal · stefanberger/libtpms@2e6173c · GitHub |
MISC |
github.com |
|
| Reset buffer size indicators that are too large and check for maximum size on marshalling by stefanberger · Pull Request #223 · stefanberger/libtpms · GitHub |
MISC |
github.com |
|
| tpm2: Reset TPM2B buffer sizes after test fails for valid buffer size · stefanberger/libtpms@2f30d62 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 34 Update: libtpms-0.8.4-1.20210624gita594c4692a.fc34.1 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159724 Oracle Enterprise Linux Security Update for libtpms (ELSA-2022-9240)
- 182922 Debian Security Update for libtpms (CVE-2021-3623)
- 281671 Fedora Security Update for libtpms (FEDORA-2021-465b5c3b67)
- 752991 SUSE Enterprise Linux Security Update for libtpms (SUSE-SU-2022:4457-1)