Bug 1902167 (CVE-2020-24455) - CVE-2020-24455 tpm2-tss: FAPI PolicyPCR not instatiating correctly
Summary: CVE-2020-24455 tpm2-tss: FAPI PolicyPCR not instatiating correctly
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: CVE-2020-24455
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1908235
Blocks: 1902168
TreeView+ depends on / blocked
 
Reported: 2020-11-27 08:10 UTC by Dhananjay Arunesh
Modified: 2021-09-28 17:00 UTC (History)
5 users (show)

Fixed In Version: tpm2-tss 2.4.3
Doc Type: If docs needed, set a value
Doc Text:
The tpm2-tss package introduced an implementation of TCG Feature API (FAPI) from v2.4.0. While instantiating TPM policy via FAPI, TPM's Platform Configuration Register (PCR) are used to compute policy digest. While reading PCR values via 'ifapi_read_pcr' routine, a PCR list counter was not set which can lead to an incorrect policy instantiation. This may potentially lead to a DoS scenario.
Clone Of:
Environment:
Last Closed: 2020-12-16 08:48:13 UTC


Attachments (Terms of Use)

Description Dhananjay Arunesh 2020-11-27 08:10:12 UTC
The tpm2-tss package has been updated to version 2.4.3, which includes a fix
for this issue and several other changes.  See the upstream release
announcements for details.

References:
https://github.com/tpm2-software/tpm2-tss/releases/tag/3.0.1
https://github.com/tpm2-software/tpm2-tss/releases/tag/2.4.3

Comment 1 Doran Moppert 2020-12-16 07:34:37 UTC
Created tpm2-tss tracking bugs for this issue:

Affects: fedora-all [bug 1908235]

Comment 2 Peter Robinson 2020-12-16 08:48:13 UTC
Long fixed in Fedora:
* tpm2-tss-3.0.1-1.fc33 - Built: 2020-09-23, pushed stable 2020-09-27
* tpm2-tss-2.4.3-1.fc32 - Built: 2020-09-23, pushed stable 2020-10-06


Note You need to log in before you can comment on or make changes to this bug.