Описание
Security update for libtpms
This update for libtpms fixes the following issues:
- CVE-2021-3746: Fixed out-of-bounds access via specially crafted TPM 2 command packets (bsc#1189935).
Список пакетов
Container suse/sles/15.3/virt-launcher:0.45.0
libtpms0-0.8.2-3.3.1
Container suse/sles/15.4/virt-launcher:0.49.0
libtpms0-0.8.2-3.3.1
Container suse/sles/15.5/virt-launcher:0.58.0
libtpms0-0.8.2-3.3.1
SUSE Linux Enterprise Module for Server Applications 15 SP3
libtpms-devel-0.8.2-3.3.1
libtpms0-0.8.2-3.3.1
Ссылки
- Link for SUSE-SU-2021:3004-1
- E-Mail link for SUSE-SU-2021:3004-1
- SUSE Security Ratings
- SUSE Bug 1189935
- SUSE CVE CVE-2021-3746 page
Описание
A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by specially-crafted TPM2 command packets that then trigger the issue when the state of the TPM2's volatile state is written. The highest threat from this vulnerability is to system availability. This issue affects libtpms versions before 0.8.5, before 0.7.9 and before 0.6.6.
Затронутые продукты
Container suse/sles/15.3/virt-launcher:0.45.0:libtpms0-0.8.2-3.3.1
Container suse/sles/15.4/virt-launcher:0.49.0:libtpms0-0.8.2-3.3.1
Container suse/sles/15.5/virt-launcher:0.58.0:libtpms0-0.8.2-3.3.1
SUSE Linux Enterprise Module for Server Applications 15 SP3:libtpms-devel-0.8.2-3.3.1
Ссылки
- CVE-2021-3746
- SUSE Bug 1189935