It was not checked whether the magic number in the attest is equal to TPM2_GENERATED_VALUE. So an attacker could generate arbitrary quote data which was not detected by tpm2 checkquote. References: https://github.com/tpm2-software/tpm2-tools/commit/66d922d6547b7b4fe4f274fb2ec10b376e0e259c
Created tpm2-tools tracking bugs for this issue: Affects: fedora-all [bug 2292187]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9424 https://access.redhat.com/errata/RHSA-2024:9424