Out-of-bounds write in Trusted Platform Module (TPM) 2.0 - CVE-2023-1017
Published: March 2, 2023 / Updated: March 3, 2023
Vulnerability identifier: #VU72706
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1017
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in the CryptParameterDecryption routine. A remote attacker can trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
Trusted Platform Module (TPM) 2.0
2nd Gen AMD Ryzen Threadripper processors
IBM Power System AC922
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Microsoft Windows
SUSE Linux Enterprise Server 15 SP3 LTSS
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Windows Server
libtpms
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libtpms-debuginfo
libtpms-devel
libtpms
libtpms-debugsource
libtpms0-debuginfo
libtpms0
libtpms (Red Hat package)
libtpms0 (Ubuntu package)
libtpms-doc
PowerVM Hypervisor
PowerProtect DP Series Appliance (IDPA)
Dell EMC VxRail Appliance
2nd Gen AMD Ryzen Threadripper processors
IBM Power System AC922
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Microsoft Windows
SUSE Linux Enterprise Server 15 SP3 LTSS
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Windows Server
libtpms
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libtpms-debuginfo
libtpms-devel
libtpms
libtpms-debugsource
libtpms0-debuginfo
libtpms0
libtpms (Red Hat package)
libtpms0 (Ubuntu package)
libtpms-doc
PowerVM Hypervisor
PowerProtect DP Series Appliance (IDPA)
Dell EMC VxRail Appliance
How to mitigate CVE-2023-1017
Install updates from vendor's website.
Trusted Platform Module (TPM) 2.0 - addressed in versions 1.16, 1.38, 1.59
libtpms - addressed in versions 0.8.9, 0.9.6
Red Hat OpenShift Container Platform - update to 4.13.2
PowerVM Hypervisor - addressed in versions FW1010.60, FW1020.40
IBM Power System AC922 - update to OP940.70
libtpms-debuginfo - update to 0.7.3-8
libtpms-devel - update to 0.7.3-8
libtpms - update to 0.7.3-8
libtpms-debugsource - update to 0.7.3-8
libtpms-devel - update to 0.8.2-150300.3.9.1
libtpms0-debuginfo - update to 0.8.2-150300.3.9.1
libtpms-debugsource - update to 0.8.2-150300.3.9.1
libtpms0 - update to 0.8.2-150300.3.9.1
libtpms (Red Hat package) - update to 0.9.1-3.20211126git1ff6fe1f43.el9_2
libtpms0 (Ubuntu package) - addressed in versions 0.9.3-0ubuntu1.22.04.1, 0.9.3-0ubuntu1.22.10.1
libtpms - addressed in versions 0.9.6-1.fc36, 0.9.6-1.fc37, 0.9.6-1.fc38
libtpms - update to 0.10.0-1
libtpms-devel - update to 0.10.0-1
libtpms-doc - update to 0.10.0-1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
Dell EMC VxRail Appliance - update to 8.0.101
libtpms - addressed in versions 0.8.9, 0.9.6
Red Hat OpenShift Container Platform - update to 4.13.2
PowerVM Hypervisor - addressed in versions FW1010.60, FW1020.40
IBM Power System AC922 - update to OP940.70
libtpms-debuginfo - update to 0.7.3-8
libtpms-devel - update to 0.7.3-8
libtpms - update to 0.7.3-8
libtpms-debugsource - update to 0.7.3-8
libtpms-devel - update to 0.8.2-150300.3.9.1
libtpms0-debuginfo - update to 0.8.2-150300.3.9.1
libtpms-debugsource - update to 0.8.2-150300.3.9.1
libtpms0 - update to 0.8.2-150300.3.9.1
libtpms (Red Hat package) - update to 0.9.1-3.20211126git1ff6fe1f43.el9_2
libtpms0 (Ubuntu package) - addressed in versions 0.9.3-0ubuntu1.22.04.1, 0.9.3-0ubuntu1.22.10.1
libtpms - addressed in versions 0.9.6-1.fc36, 0.9.6-1.fc37, 0.9.6-1.fc38
libtpms - update to 0.10.0-1
libtpms-devel - update to 0.10.0-1
libtpms-doc - update to 0.10.0-1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
Dell EMC VxRail Appliance - update to 8.0.101
External References
Related Security Bulletins
- Multiple vulnerabilities in Trusted Computing Group TPM 2.0
- Multiple vulnerabilities in libtpms
- Ubuntu update for libtpms
- Out-of-bounds write in Microsoft Windows and Windows Server
- Multiple vulnerabilities in 2nd Gen AMD Ryzen Threadripper processors
- Red Hat Enterprise Linux 8.6 Extended Update Support update for the virt:rhel and virt-devel:rhel modules
- SUSE update for libtpms
- Red Hat Enterprise Linux 9 update for libtpms
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM PowerVM Hypervisor
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Fedora 38 update for libtpms
- Fedora 37 update for libtpms
- Fedora 36 update for libtpms
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- openEuler update for libtpms
- Multiple vulnerabilities in IBM Power System AC922
- Multiple vulnerabilities in Dell PowerProtect DP Series Appliance (IDPA)
- Anolis OS update for libtpms