SB2025122235 - Anolis OS update for tpm2-tools
Published: December 22, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: CVE-2024-29039)
The vulnerability allows a local user to manipulate the TMP state.
The vulnerability exists due to insufficient validation of PCR input. A local user can alter TPML_PCR_SELECTION and manipulate the TMP state.
Remediation
Install update from vendor's website.