Out-of-bounds read in swtpm - CVE-2022-23645

 

Out-of-bounds read in swtpm - CVE-2022-23645

Published: February 21, 2022 / Updated: December 2, 2022


Vulnerability identifier: #VU60731
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23645
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition when the byte array representing the state of the TPM is accessed. A remote attacker can send a specially crafted header, trigger out-of-bounds read error and cause a denial of service condition on the system.


Affected software

swtpm
Oracle Linux
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
openSUSE Leap
openEuler
Fedora
swtpm
swtpm-libs
swtpm-debuginfo
swtpm-devel
swtpm-tools
swtpm-debugsource
swtpm (Red Hat package)

How to mitigate CVE-2022-23645

Install updates from vendor's website.

swtpm - addressed in versions 0.5.3, 0.6.2, 0.7.1
swtpm - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-libs - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-debuginfo - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-devel - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-tools - addressed in versions 0.3.3-3, 0.3.3-6
swtpm-debugsource - addressed in versions 0.3.3-3, 0.3.3-6
swtpm - update to 0.5.3-150300.3.3.1
swtpm-devel - update to 0.5.3-150300.3.3.1
swtpm-debugsource - update to 0.5.3-150300.3.3.1
swtpm-debuginfo - update to 0.5.3-150300.3.3.1
swtpm (Red Hat package) - update to 0.7.0-3.20211109gitb79fd91.el9
swtpm - update to 0.7.1-1.20220218git92a7035.fc35

External References

Related Security Bulletins