RHSA-2024:9424: Low: tpm2-tools security update
Low: tpm2-tools security update
Other sources
The tpm2-tools packages add a set of utilities for management and utilization of Trusted Platform Module (TPM) 2.0 devices from user space.<br>Security Fix(es):<br><li> tpm2-tools: arbitrary quote data may go undetected by tpm2checkquote (CVE-2024-29038)</li> <li> tpm2-tools: pcr selection value is not compared with the attest (CVE-2024-29039)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Additional Changes:<br>For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the significance of RHSA-2024:9424?
RHSA-2024:9424 addresses a security vulnerability affecting tpm2-tools that allows arbitrary quote data to go undetected by tpm2_checkquote.
How can I mitigate the vulnerability described in RHSA-2024:9424?
To mitigate the vulnerability in RHSA-2024:9424, users should update to the patched version 5.2-4.el9 of tpm2-tools.
What systems are affected by RHSA-2024:9424?
RHSA-2024:9424 impacts multiple architectures of Red Hat Enterprise Linux including x86_64, Power, IBM z Systems, and ARM 64.
Is there a specific version I need to upgrade to for RHSA-2024:9424?
Yes, for RHSA-2024:9424, you need to upgrade tpm2-tools to version 5.2-4.el9.
What kind of risk does RHSA-2024:9424 pose to systems?
The risk posed by RHSA-2024:9424 involves potential unauthorized detection of arbitrary quote data, which may compromise the integrity of a Trusted Platform Module.