tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in the PCR input file. As a result, digest values are incorrectly mapped to PCR slots and banks, providing a misleading picture of the TPM state. This issue has been patched in version 5.7.
CVSS Details
- CVSS 3.1 Base Score: 9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tpm2-tools | Nov 19, 2024 | Jun 28, 2024 |
| Alpine Linux | — | Upgrade tpm2-tools | Aug 8, 2025 | Jun 28, 2024 |
| Amazon_linux_2023 | — | Upgrade tpm2-tools-debugsourceUpgrade tpm2-tools-debuginfoUpgrade tpm2-tools | Feb 17, 2025 | Apr 30, 2024 |
| Debian | — | Upgrade tpm2-toolsNo solution exists | May 15, 2025 | Jun 28, 2024 |
| Oracle_linux | — | Upgrade tpm2-tools | Nov 21, 2024 | Apr 30, 2024 |
| Redhat_linux | — | Upgrade tpm2-tools-debuginfoNo solution existsUpgrade tpm2-toolsUpgrade tpm2-tools-debugsource | Nov 13, 2024 | Jun 28, 2024 |
| Rocky_linux | — | Upgrade tpm2-toolsUpgrade tpm2-tools-debugsourceUpgrade tpm2-tools-debuginfo | Mar 18, 2025 | Jun 28, 2024 |
| Suse | — | Upgrade tpm2.0-tools | May 15, 2024 | May 14, 2024 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jun 28, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 28, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub