The pcr selection which is passed with the --pcr parameter it not compared with the attest. So it's possible to fake a valid attestation. References: https://github.com/tpm2-software/tpm2-tools/commit/98599df9392a346216c5a059b8d35271286100bb
Created tpm2-tools tracking bugs for this issue: Affects: fedora-all [bug 2292188]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9424 https://access.redhat.com/errata/RHSA-2024:9424