First published: Fri Jun 28 2024(Updated: )
Last updated 24 July 2024
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/tpm2-tss | <=3.0.3-2<=3.2.1-3<=4.0.1-7.2 | 4.1.3-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29040 has been classified as a moderate severity vulnerability.
To fix CVE-2024-29040, you need to upgrade to the version 4.1.3-1 or later of the tpm2-tss package.
CVE-2024-29040 affects tpm2-tss versions up to and including 4.0.1-7.2.
CVE-2024-29040 impacts systems that run the tpm2-tss package on Debian.
The vulnerability in CVE-2024-29040 is found in the deserialization process of the JSON Quote Info returned by the Fapi_Quote function.