CVE-2022-23645
published 2022-02-18CVE-2022-23645: swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to…
medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | swtpm | < swtpm 0.7.1-1 (bookworm) | swtpm 0.7.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| stefanberger | swtpm | < 0.5.3 | 0.5.3 |
| stefanberger | swtpm | — | — |
| stefanberger | swtpm | — | — |
| swtpm_project | swtpm | < 0.5.3 | 0.5.3 |
| swtpm_project | swtpm | — | — |
| swtpm_project | swtpm | >= 0 < 0.7.1-1 | 0.7.1-1 |
| swtpm_project | swtpm | >= 0 < 0.7.1-1 | 0.7.1-1 |
| swtpm_project | swtpm | >= 0 < 0.7.1-1 | 0.7.1-1 |
| swtpm_project | swtpm | >= 0.6.0 < 0.6.2 | 0.6.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
Red Hat
swtpm: Unchecked header size indicator against expected size
vendor_redhat·2022-02-18·CVSS 6.2
CVE-2022-23645 [MEDIUM] CWE-125 swtpm: Unchecked header size indicator against expected size
swtpm: Unchecked header size indicator against expected size
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.
An out-of-bounds read vulnerability was found in swtpm. The vulnerability exists due to a boundary condition when the byte array representin
Debian
CVE-2022-23645: swtpm - swtpm is a libtpms-based TPM emulator with socket, character device, and Linux C...
vendor_debian·2022·CVSS 6.2
CVE-2022-23645 [MEDIUM] CVE-2022-23645: swtpm - swtpm is a libtpms-based TPM emulator with socket, character device, and Linux C...
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.
Scope: local
bookworm: resolved (fixed in 0.7.1-1)
forky: resolved (fixed in 0.7.1-1)
sid: resolved (fixed in 0.7.1-1)
trixie: resolved (fixed in 0.7.1-1)
OSV
CVE-2022-23645: swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface
osv·2022-02-18·CVSS 5.5
CVE-2022-23645 [MEDIUM] CVE-2022-23645: swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/stefanberger/swtpm/commit/9f740868fc36761de27df3935513bdebf8852d19https://github.com/stefanberger/swtpm/releases/tag/v0.5.3https://github.com/stefanberger/swtpm/releases/tag/v0.6.2https://github.com/stefanberger/swtpm/releases/tag/v0.7.1https://github.com/stefanberger/swtpm/security/advisories/GHSA-2qgm-8xf4-3hqwhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WL735FW266GO4C2JX4CJBOIOB7R7AY5A/https://github.com/stefanberger/swtpm/commit/9f740868fc36761de27df3935513bdebf8852d19https://github.com/stefanberger/swtpm/releases/tag/v0.5.3https://github.com/stefanberger/swtpm/releases/tag/v0.6.2https://github.com/stefanberger/swtpm/releases/tag/v0.7.1https://github.com/stefanberger/swtpm/security/advisories/GHSA-2qgm-8xf4-3hqwhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WL735FW266GO4C2JX4CJBOIOB7R7AY5A/
2022-02-18
Published