CVE-2017-16837: Input Validation
Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to overwrite dynamic PCRs of Trusted Platform Module (TPM) by hooking these function pointers.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-16837?
CVE-2017-16837 is classified with a high severity level due to the potential for arbitrary code execution.
How do I fix CVE-2017-16837?
To fix CVE-2017-16837, upgrade to a version of Trusted Boot beyond 1.9.6 that addresses the validation of function pointers.
Who is affected by CVE-2017-16837?
CVE-2017-16837 affects users and systems using Trusted Boot version 1.9.6.
What are the potential impacts of CVE-2017-16837?
The impacts of CVE-2017-16837 can include local users gaining elevated privileges and the ability to overwrite dynamic PCRs of the TPM.
Is CVE-2017-16837 related to TPM security?
Yes, CVE-2017-16837 directly affects the security of the Trusted Platform Module through the manipulation of dynamic PCRs.