tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in the PCR input file. As a result, digest values are incorrectly mapped to PCR slots and banks, providing a misleading picture of the TPM state. This issue has been patched in version 5.7.
An attacker can supply a crafted PCR input file with a modified TPML_PCR_SELECTION structure, causing incorrect mapping of digest values to PCR slots and banks. As a result, the tpm2_checkquote tool presents incorrect TPM state data, failing to detect actual discrepancies. The vulnerability is classified as CWE-807 (Reliance on Untrusted Inputs in a Security Decision), meaning security decisions are made based on untrusted, unverified input data.
An attacker can cause system integrity verification processes based on TPM 2.0 to return false positive results, concealing the actual platform state. This could lead to acceptance of a compromised system as trusted, exposing the environment to further attacks with full breach of confidentiality, integrity, and availability.
Update tpm2-tools to version 5.7 or later, which contains the patched vulnerability. Packages for Fedora distributions are available through official repositories. Details are available in the vendor references.
tpm2-tools (tpm2-software project) — all versions before 5.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HTpm2 Tools Project Tpm2 Tools
APPTpm2-Tools Project< 5.7
Related vulnerabilities
tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can g...
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for...
tpm2-tools versions before 1.1.1 are vulnerable to a password leak due to transmitting password in plaintext f...