Back to bug 1964427

Who When What Removed Added
Guilherme de Almeida Suckevicz 2021-05-25 13:26:48 UTC Blocks 1964430
Guilherme de Almeida Suckevicz 2021-05-25 13:26:55 UTC Depends On 1964429, 1964428
Red Hat Bugzilla 2021-05-30 12:37:33 UTC CC bhu
Mauro Matteo Cascella 2021-05-31 09:45:50 UTC Fixed In Version tpm2-tools 5.1.1, tpm2-tools 4.3.2
Mauro Matteo Cascella 2021-05-31 10:02:47 UTC Depends On 1965982, 1965981
Mauro Matteo Cascella 2021-05-31 10:13:45 UTC Doc Text A flaw was found in tpm2-tools. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.
Mauro Matteo Cascella 2021-05-31 10:23:34 UTC Summary CVE-2021-3565 tpm2-tools: during tpm2_import command invocation a fixed AES wrapping key is used CVE-2021-3565 tpm2-tools: fixed AES wrapping key in tpm2_import
Jeff Fearn 🐞 2021-06-03 11:58:13 UTC CC bhu
errata-xmlrpc 2021-11-09 18:41:56 UTC Link ID Red Hat Product Errata RHSA-2021:4413
Product Security DevOps Team 2021-11-10 00:22:26 UTC Status NEW CLOSED
Resolution --- ERRATA
Last Closed 2021-11-10 00:22:26 UTC
Rafael Aquini 2023-08-08 02:58:56 UTC CC core-kernel-mgr core-kernel-mgr

Back to bug 1964427