tpm2-tss is a software stack supporting Trusted Platform Module(TPM) 2.0 system APIs which provides TPM2.0 specified APIs for applications to access TPM module through kernel TPM drivers.
Security Fix(es):
A flaw was found in the tpm2-tss package, where it was not checked to see if the magic number in the attest is equal to the TPM2_GENERATED_VALUE. This flaw allows an attacker to generate arbitrary quote data, which may not be detected by Fapi_VerifyQuote.(CVE-2024-29040)
{
"severity": "Medium"
}{
"aarch64": [
"tpm2-tss-devel-3.0.3-3.oe2003sp4.aarch64.rpm",
"tpm2-tss-debugsource-3.0.3-3.oe2003sp4.aarch64.rpm",
"tpm2-tss-debuginfo-3.0.3-3.oe2003sp4.aarch64.rpm",
"tpm2-tss-3.0.3-3.oe2003sp4.aarch64.rpm"
],
"noarch": [
"tpm2-tss-help-3.0.3-3.oe2003sp4.noarch.rpm"
],
"src": [
"tpm2-tss-3.0.3-3.oe2003sp4.src.rpm"
],
"x86_64": [
"tpm2-tss-devel-3.0.3-3.oe2003sp4.x86_64.rpm",
"tpm2-tss-3.0.3-3.oe2003sp4.x86_64.rpm",
"tpm2-tss-debuginfo-3.0.3-3.oe2003sp4.x86_64.rpm",
"tpm2-tss-debugsource-3.0.3-3.oe2003sp4.x86_64.rpm"
]
}