Insufficient Entropy in libtpms - CVE-2021-3505

 

Insufficient Entropy in libtpms - CVE-2021-3505

Published: July 1, 2021


Vulnerability identifier: #VU54502
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3505
CWE-ID: CWE-331
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to decrypt data.

The vulnerability exists in the TPM 2 implementation, which returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check.


Affected software

libtpms
openEuler
Fedora
PowerVM Hypervisor
libtpms
libtpms-debugsource
libtpms-devel
libtpms-debuginfo

How to mitigate CVE-2021-3505

Install updates from vendor's website.

libtpms - update to 0.8.0
PowerVM Hypervisor - update to FW1050.00
libtpms - update to 0.7.3-7
libtpms-debugsource - update to 0.7.3-7
libtpms-devel - update to 0.7.3-7
libtpms-debuginfo - update to 0.7.3-7
libtpms - update to 0.8.2-0.20210426git729fc6a4ca.fc33

External References

Related Security Bulletins