This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This issue has been patched in version 4.1.0.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-tpm2-tss | Aug 22, 2024 | Jun 28, 2024 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-tpm2-tssamazon-linux-2023-upgrade-tpm2-tss-debuginfoamazon-linux-2023-upgrade-tpm2-tss-debugsourceamazon-linux-2023-upgrade-tpm2-tss-develamazon-linux-2023-upgrade-tpm2-tss-fapiamazon-linux-2023-upgrade-tpm2-tss-fapi-debuginfo | Feb 17, 2025 | Apr 30, 2024 | |
| Debian | no-fix-debian-deb-package | May 15, 2025 | Jun 28, 2024 | |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-tpm2-tss | Jul 16, 2024 | Jun 28, 2024 | |
| Huawei Euleros 2_0_sp11 | huawei-euleros-2_0_sp11-upgrade-tpm2-tss | Oct 8, 2024 | Jun 28, 2024 | |
| Huawei Euleros 2_0_sp12 | huawei-euleros-2_0_sp12-upgrade-tpm2-tss | Oct 8, 2024 | Jun 28, 2024 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-tpm2-tss | Jul 17, 2024 | Jun 28, 2024 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Jun 28, 2024 |
| Suse | — | suse-upgrade-libtss2-esys0suse-upgrade-libtss2-esys0-32bitsuse-upgrade-libtss2-fapi-commonsuse-upgrade-libtss2-fapi1suse-upgrade-libtss2-fapi1-32bitsuse-upgrade-libtss2-mu0suse-upgrade-libtss2-mu0-32bitsuse-upgrade-libtss2-policy0suse-upgrade-libtss2-rc0suse-upgrade-libtss2-rc0-32bitsuse-upgrade-libtss2-sys1suse-upgrade-libtss2-sys1-32bitsuse-upgrade-libtss2-tcti-cmd0suse-upgrade-libtss2-tcti-cmd0-32bitsuse-upgrade-libtss2-tcti-device0suse-upgrade-libtss2-tcti-device0-32bitsuse-upgrade-libtss2-tcti-i2c-helper0suse-upgrade-libtss2-tcti-mssim0suse-upgrade-libtss2-tcti-mssim0-32bitsuse-upgrade-libtss2-tcti-pcap0suse-upgrade-libtss2-tcti-spi-helper0suse-upgrade-libtss2-tcti-spidev0suse-upgrade-libtss2-tcti-swtpm0suse-upgrade-libtss2-tcti-swtpm0-32bitsuse-upgrade-libtss2-tctildr0suse-upgrade-libtss2-tctildr0-32bitsuse-upgrade-tpm2-0-tsssuse-upgrade-tpm2-0-tss-devel | May 15, 2024 | May 10, 2024 |
| Ubuntu | ubuntu-upgrade-libtss2-esys-3-0-2-0ubuntu-upgrade-libtss2-esys-3-0-2-0t64ubuntu-upgrade-libtss2-esys0ubuntu-upgrade-libtss2-fapi1ubuntu-upgrade-libtss2-fapi1t64ubuntu-upgrade-libtss2-mu-4-0-1-0t64ubuntu-upgrade-libtss2-mu0ubuntu-upgrade-libtss2-policy0ubuntu-upgrade-libtss2-policy0t64ubuntu-upgrade-libtss2-rc0ubuntu-upgrade-libtss2-rc0t64ubuntu-upgrade-libtss2-sys1ubuntu-upgrade-libtss2-sys1t64ubuntu-upgrade-libtss2-tcti-cmd0ubuntu-upgrade-libtss2-tcti-cmd0t64ubuntu-upgrade-libtss2-tcti-device0ubuntu-upgrade-libtss2-tcti-device0t64ubuntu-upgrade-libtss2-tcti-libtpms0ubuntu-upgrade-libtss2-tcti-libtpms0t64ubuntu-upgrade-libtss2-tcti-mssim0ubuntu-upgrade-libtss2-tcti-mssim0t64ubuntu-upgrade-libtss2-tcti-pcap0ubuntu-upgrade-libtss2-tcti-pcap0t64ubuntu-upgrade-libtss2-tcti-spi-helper0ubuntu-upgrade-libtss2-tcti-spi-helper0t64ubuntu-upgrade-libtss2-tcti-swtpm0ubuntu-upgrade-libtss2-tcti-swtpm0t64ubuntu-upgrade-libtss2-tctildr0ubuntu-upgrade-libtss2-tctildr0t64 | Jun 6, 2024 | May 29, 2024 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jul 2, 2025 | Jun 28, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub