USN-6796-1: TPM2 Software Stack vulnerabilities
Fergus Dall discovered that TPM2 Software Stack did not properly handle layer arrays. An attacker could possibly use this issue to cause TPM2 Software Stack to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-22745) Jurgen Repp and Andreas Fuchs discovered that TPM2 Software Stack did not validate the quote data after deserialization. An attacker could generate an arbitrary quote and cause TPM2 Software Stack to have unknown behavior. (CVE-2024-29040)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6796-1?
The severity of USN-6796-1 is classified as a denial of service vulnerability that could allow an attacker to crash the TPM2 Software Stack.
How do I fix USN-6796-1?
To fix USN-6796-1, you need to update to the affected package versions 4.0.1-7.1ubuntu5.1 or later.
What products are affected by USN-6796-1?
USN-6796-1 affects Ubuntu 24.04 and various libtss2 packages, including libtss2-esys, libtss2-fapi, and more.
What can an attacker achieve with USN-6796-1?
An attacker exploiting USN-6796-1 could potentially cause a denial of service or execute arbitrary code on the affected systems.
Is there a known exploit for USN-6796-1?
As of now, there are no publicly known exploits specifically targeting USN-6796-1.