CVE-2024-29038: tpm2 does not detect if quote was not generated by TPM

Published May 1, 2024
·
Updated

It was not checked whether the magic number in the attest is equal to TPM2GENERATEDVALUE. So an attacker could generate arbitrary quote data which was not detected by tpm2 checkquote.

References: https://github.com/tpm2-software/tpm2-tools/commit/66d922d6547b7b4fe4f274fb2ec10b376e0e259c

Other sources

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by tpm2 checkquote. This issue was patched in version 5.7.

NVD

Affected Software

3 affected componentsFixes available
redhat/tpm2-tools<5.7
5.7
Tpm2-tools Project Tpm2-tools>=4.1<5.5.1
Tpm2-tools Project Tpm2-tools>5.6.1<5.7

Event History

Jun 28, 2024
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-29038?

CVE-2024-29038 has a high severity due to the potential for attackers to generate arbitrary quote data unchecked by tpm2 checkquote.

2

How do I fix CVE-2024-29038?

To fix CVE-2024-29038, you should upgrade to tpm2-tools version 5.7 or later.

3

What does CVE-2024-29038 affect?

CVE-2024-29038 affects the tpm2-tools package provided by Red Hat.

4

What could an attacker achieve by exploiting CVE-2024-29038?

An attacker could exploit CVE-2024-29038 to generate arbitrary quote data that bypasses detection mechanisms.

5

Is CVE-2024-29038 related to TPM security?

Yes, CVE-2024-29038 is directly related to security issues in the Trusted Platform Module (TPM) implementations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203