Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:9424

Опубликовано: 17 мар. 2025
Источник: rocky
Оценка: Low

Описание

Low: tpm2-tools security update

The tpm2-tools packages add a set of utilities for management and utilization of Trusted Platform Module (TPM) 2.0 devices from user space.

Security Fix(es):

  • tpm2-tools: arbitrary quote data may go undetected by tpm2_checkquote (CVE-2024-29038)

  • tpm2-tools: pcr selection value is not compared with the attest (CVE-2024-29039)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
tpm2-toolsx86_644.el9tpm2-tools-5.2-4.el9.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

suse-cvrf
больше 1 года назад

Security update for tpm2.0-tools

oracle-oval
около 1 года назад

ELSA-2024-9424: tpm2-tools security update (LOW)

CVSS3: 4.3
ubuntu
больше 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

CVSS3: 4.4
redhat
больше 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.

CVSS3: 4.3
nvd
больше 1 года назад

tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.