REDHAT-BUG-2149416: Medium severity Trusted Computing Group TPM2.0 Module Library vulnerability
A out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2149416?
The severity of REDHAT-BUG-2149416 is classified as critical due to the potential for denial of service.
What causes the vulnerability REDHAT-BUG-2149416?
The vulnerability REDHAT-BUG-2149416 is caused by an out-of-bounds write in the TPM2.0 Module Library's CryptParameterDecryption routine.
How do I fix REDHAT-BUG-2149416?
To fix REDHAT-BUG-2149416, update to the latest version of the Trusted Computing Group TPM2.0 Module Library.
What could happen if REDHAT-BUG-2149416 is exploited?
Exploiting REDHAT-BUG-2149416 could result in denial of service by crashing the TPM chip or process.
Which software is affected by REDHAT-BUG-2149416?
The affected software for REDHAT-BUG-2149416 is the Trusted Computing Group TPM2.0 Module Library.