CVE-2021-3565: Infoleak
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.
Other sources
During tpm2import command invocation a fixed AES wrapping key is used. This presents a weakness in that, when no encrypted session with the TPM is used, the encrypted inner wrapper key is known and thus an entity performing an MITM on the TPM would be able to unwrap the inner portion and reveal the key being imported.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/tpm2-toolsto a version that resolves this vulnerability.Fixed in 5.1.1 - Upgrade
Upgrade
redhat/tpm2-toolsto a version that resolves this vulnerability.Fixed in 4.3.2 - Upgrade
Upgrade
tpm2-toolsto a version that resolves this vulnerability.Fixed in 5.1.1 - Upgrade
Upgrade
tpm2-toolsto a version that resolves this vulnerability.Fixed in 4.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3565?
CVE-2021-3565 has a high severity rating due to its potential impact on data confidentiality.
How do I fix CVE-2021-3565?
To fix CVE-2021-3565, upgrade tpm2-tools to version 5.1.1 or above if using the 5.x series, or to version 4.3.2 if using the 4.x series.
Which versions of tpm2-tools are affected by CVE-2021-3565?
tpm2-tools versions before 5.1.1 and 4.3.2 are affected by CVE-2021-3565.
What type of attack does CVE-2021-3565 make possible?
CVE-2021-3565 potentially allows a man-in-the-middle (MITM) attacker to unwrap the inner portion and reveal the key being imported.
Is there a workaround for CVE-2021-3565?
No specific workarounds are recommended for CVE-2021-3565; updating to the fixed versions is the best approach.