Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-38576

Опубликовано: 03 янв. 2022
Источник: debian

Описание

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
edk2fixed2021.11-1package
edk2no-dsabusterpackage

Примечания

  • https://bugzilla.tianocore.org/show_bug.cgi?id=3499

  • Fixed by https://github.com/tianocore/edk2/pull/1968

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

CVSS3: 7.5
nvd
около 4 лет назад

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

CVSS3: 7.5
github
около 4 лет назад

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость библиотеки Tianocore edk2, связанная с ошибками при освобождении ресурсов, позволяющая нарушителю вызвать отказ в обслуживании