First published: Wed May 29 2024(Updated: )
Fergus Dall discovered that TPM2 Software Stack did not properly handle layer arrays. An attacker could possibly use this issue to cause TPM2 Software Stack to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-22745) Jurgen Repp and Andreas Fuchs discovered that TPM2 Software Stack did not validate the quote data after deserialization. An attacker could generate an arbitrary quote and cause TPM2 Software Stack to have unknown behavior. (CVE-2024-29040)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libtss2-esys-3.0.2-0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-fapi1t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-mu-4.0.1-0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-policy0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-rc0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-sys1t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-tcti-cmd0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-tcti-device0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-tcti-libtpms0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-tcti-mssim0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-tcti-pcap0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-tcti-spi-helper0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-tcti-swtpm0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-tctildr0t64 | <4.0.1-7.1ubuntu5.1 | 4.0.1-7.1ubuntu5.1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/libtss2-esys-3.0.2-0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-fapi1 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-mu0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-policy0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-rc0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-sys1 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-tcti-cmd0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-tcti-device0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-tcti-libtpms0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-tcti-mssim0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-tcti-pcap0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-tcti-spi-helper0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-tcti-swtpm0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-tctildr0 | <4.0.1-3ubuntu1.1 | 4.0.1-3ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/libtss2-esys-3.0.2-0 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-fapi1 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-mu0 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-rc0 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-sys1 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-tcti-cmd0 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-tcti-device0 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-tcti-mssim0 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-tcti-swtpm0 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-tctildr0 | <3.2.0-1ubuntu1.1 | 3.2.0-1ubuntu1.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/libtss2-esys0 | <2.3.2-1ubuntu0.20.04.2 | 2.3.2-1ubuntu0.20.04.2 |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-6796-1 is classified as a denial of service vulnerability that could allow an attacker to crash the TPM2 Software Stack.
To fix USN-6796-1, you need to update to the affected package versions 4.0.1-7.1ubuntu5.1 or later.
USN-6796-1 affects Ubuntu 24.04 and various libtss2 packages, including libtss2-esys, libtss2-fapi, and more.
An attacker exploiting USN-6796-1 could potentially cause a denial of service or execute arbitrary code on the affected systems.
As of now, there are no publicly known exploits specifically targeting USN-6796-1.