CVE-2023-1017
Summary
| CVE | CVE-2023-1017 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-28 19:15:00 UTC |
| Updated | 2024-04-01 15:50:00 UTC |
| Description | An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160624 Oracle Enterprise Linux Security Update for libtpms (ELSA-2023-2453)
- 183386 Debian Security Update for libtpms (CVE-2023-1017)
- 199222 Ubuntu Security Notification for Libtpms Vulnerabilities (USN-5933-1)
- 241358 Red Hat Update for virt:rhel and virt-devel:rhel (RHSA-2023:1833)
- 241437 Red Hat Update for libtpms (RHSA-2023:2453)
- 283760 Fedora Security Update for libtpms (FEDORA-2023-c487bde4b4)
- 283795 Fedora Security Update for libtpms (FEDORA-2023-4afddd37a9)
- 284266 Fedora Security Update for libtpms (FEDORA-2023-64f2a84db1)
- 378058 TPM 2.0 library memory corruption vulnerabilities (TCGVRT0007)
- 753950 SUSE Enterprise Linux Security Update for libtpms (SUSE-SU-2023:2051-1)
- 91990 Microsoft Windows Security Update for March 2023
- 91996 Microsoft Azure Stack Hub Security Updates for March 2023
- 941022 AlmaLinux Security Update for libtpms (ALSA-2023:2453)