tpm2-tss is a software stack supporting Trusted Platform Module(TPM) 2.0 system APIs which provides TPM2.0 specified APIs for applications to access TPM module through kernel TPM drivers.
Security Fix(es):
A flaw was found in the tpm2-tss package, where it was not checked to see if the magic number in the attest is equal to the TPM2GENERATEDVALUE. This flaw allows an attacker to generate arbitrary quote data, which may not be detected by Fapi_VerifyQuote.(CVE-2024-29040)
{ "severity": "Medium" }
{ "aarch64": [ "tpm2-tss-debugsource-3.1.0-5.oe2203sp1.aarch64.rpm", "tpm2-tss-debuginfo-3.1.0-5.oe2203sp1.aarch64.rpm", "tpm2-tss-devel-3.1.0-5.oe2203sp1.aarch64.rpm", "tpm2-tss-3.1.0-5.oe2203sp1.aarch64.rpm" ], "x86_64": [ "tpm2-tss-debugsource-3.1.0-5.oe2203sp1.x86_64.rpm", "tpm2-tss-debuginfo-3.1.0-5.oe2203sp1.x86_64.rpm", "tpm2-tss-devel-3.1.0-5.oe2203sp1.x86_64.rpm", "tpm2-tss-3.1.0-5.oe2203sp1.x86_64.rpm" ], "noarch": [ "tpm2-tss-help-3.1.0-5.oe2203sp1.noarch.rpm" ], "src": [ "tpm2-tss-3.1.0-5.oe2203sp1.src.rpm" ] }