Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.
CVSS Details
- CVSS 3.1 Base Score: 6.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade tpm2-tss | Jul 30, 2024 | Feb 26, 2021 |
| Gentoo Linux | — | Upgrade app-crypt/tpm2-tss. | Jul 8, 2021 | Feb 26, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade tpm2-tss | Feb 8, 2021 | Feb 5, 2021 |
| Suse | — | Upgrade libtss2-rc0Upgrade libtss2-tcti-mssim0Upgrade libtss2-tctildr0Upgrade libtss2-tcti-device0Upgrade tpm2-0-tss-develUpgrade libtss2-sys0Upgrade libtss2-fapi0Upgrade libtss2-mu0Upgrade tpm2-0-tssUpgrade libtss2-esys0 | Feb 4, 2022 | Feb 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub