Out-of-bounds read in swtpm - CVE-2022-23645
Published: February 21, 2022 / Updated: December 2, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when the byte array representing the state of the TPM is accessed. A remote attacker can send a specially crafted header, trigger out-of-bounds read error and cause a denial of service condition on the system.
Affected software
Oracle Linux
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Fedora
swtpm
swtpm-libs
swtpm-debuginfo
swtpm-devel
swtpm-tools
swtpm-debugsource
swtpm (Red Hat package)
How to mitigate CVE-2022-23645
swtpm - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-libs - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-debuginfo - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-devel - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-tools - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-debugsource - addressed in versions 0.3.3-3, 0.3.3-6
swtpm - update to 0.5.3-150300.3.3.1
swtpm-devel - update to 0.5.3-150300.3.3.1
swtpm-debugsource - update to 0.5.3-150300.3.3.1
swtpm-debuginfo - update to 0.5.3-150300.3.3.1
swtpm (Red Hat package) - update to 0.7.0-3.20211109gitb79fd91.el9
swtpm - update to 0.7.1-1.20220218git92a7035.fc35
External References
- https://github.com/stefanberger/swtpm/security/advisories/GHSA-2qgm-8xf4-3hqw
- https://github.com/stefanberger/swtpm/commit/9f740868fc36761de27df3935513bdebf8852d19
- https://github.com/stefanberger/swtpm/releases/tag/v0.5.3
- https://github.com/stefanberger/swtpm/releases/tag/v0.6.2
- https://github.com/stefanberger/swtpm/releases/tag/v0.7.1
- https://github.com/stefanberger/swtpm/releases/tag/v0.8.0
Related Security Bulletins
- Denial of service in Software TPM Emulator (SWTPM)
- Red Hat Enterprise Linux 8 update for the virt:rhel and virt-devel:rhel modules
- Red Hat Enterprise Linux 9 update for swtpm
- SUSE update for swtpm
- Multiple vulnerabilities in Oracle Linux
- openEuler update for swtpm
- openEuler 22.03 LTS update for swtpm
- Fedora 35 update for swtpm