CVE-2024-29038

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-29038
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29038.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-29038
Aliases
  • GHSA-5495-c38w-gr6f
Downstream
Related
Published
2024-06-28T13:44:07Z
Modified
2025-11-06T01:18:25.632713Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
tpm2 does not detect if quote was not generated by TPM
Details

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by tpm2 checkquote. This issue was patched in version 5.7.

Database specific
{
    "cwe_ids": [
        "CWE-1283",
        "CWE-1390"
    ]
}
References

Affected packages

Git / github.com/tpm2-software/tpm2-tools

Affected ranges

Type
GIT
Repo
https://github.com/tpm2-software/tpm2-tools
Events

Affected versions

4.*

4.1
4.1-rc0
4.1-rc1
4.1.1
4.1.1-RC0
4.1.1-RC1
4.1.2
4.1.2-rc0
4.1.3
4.1.3-rc0
4.2
4.2-RC0
4.2-rc1
4.2.1
4.2.1-rc0
4.2.1-rc1
4.3.0
4.3.0-rc0
4.3.0-rc1

5.*

5.0
5.0-rc0
5.1
5.1-rc0
5.1-rc1
5.1.1
5.1.1-rc0
5.2
5.2-rc0
5.3
5.3-rc0
5.3-rc1
5.4
5.4-rc0
5.5
5.5-rc0
5.5-rc1
5.6
5.6-rc0
5.7-rc0
5.7-rc1

Other

ajay-kish-pub