CVE-2022-49286: tpm: use try_get_ops() in tpm-space.c

Published Feb 26, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

tpm: use trygetops() in tpm-space.c

As part of the series conversion to remove nested TPM operations:

https://lore.kernel.org/all/20190205224723.19671-1-jarkko.sakkinen@linux.intel.com/

exposure of the chip->tpmmutex was removed from much of the upper level code. In this conversion, tpm2delspace() was missed. This didn't matter much because it's usually called closely after a converted operation, so there's only a very tiny race window where the chip can be removed before the space flushing is done which causes a NULL deref on the mutex. However, there are reports of this window being hit in practice, so fix this by converting tpm2delspace() to use tpmtrygetops(), which performs all the teardown checks before acquring the mutex.

Affected Software

6 affected components
Linux Linux kernel
Linux Linux kernel>=4.12<5.4.188
Linux Linux kernel>=5.5<5.10.109
Linux Linux kernel>=5.11<5.15.32
Linux Linux kernel>=5.16<5.16.18
Linux Linux kernel=5.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel to a version that resolves this vulnerability.

    Patch tpm: use try_get_ops() in tpm-space.c
  2. Configuration

    Update the Linux kernel TPM space handling code so it uses tpm_try_get_ops() (performing all teardown checks before acquiring mutex), and ensure tpm2_del_space() is converted so chip removal cannot occur after space flushing begins (closing the NULL deref race window).

    tpm-space.c / TPM driver Use tpm_try_get_ops() in place of direct ops access (per fix: tpm: use try_get_ops() in tpm-space.c) = enabled

Event History

Feb 26, 2025
CVE Published
via MITRE·01:56 AM
Data Sourced
via MITRE·01:56 AM
Description
Data Sourced
via NVD·07:01 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Under what conditions can this issue be triggered?

The race occurs when tpm2_del_space() is flushing TPM space while the TPM chip is being removed. The affected window is described as very small, but it has been observed in practice.

2

What level of access does an attacker need?

The supplied CVSS vector indicates local access, low privileges, no user interaction, and high attack complexity. No network access is indicated.

3

What is the likely impact if the race is hit?

Removal of the chip during space flushing can cause a NULL dereference on the TPM mutex. The CVSS vector indicates an availability impact, with no confidentiality or integrity impact.

4

What does the fix change?

The fix converts tpm2_del_space() to use tpm_try_get_ops(). This performs TPM teardown checks before acquiring the mutex, preventing use of the mutex after chip removal.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203