Out-of-bounds write in Trusted Platform Module (TPM) 2.0 - CVE-2023-1017

 

Out-of-bounds write in Trusted Platform Module (TPM) 2.0 - CVE-2023-1017

Published: March 2, 2023 / Updated: March 3, 2023


Vulnerability identifier: #VU72706
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1017
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input in the CryptParameterDecryption routine. A remote attacker can trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

Trusted Platform Module (TPM) 2.0
2nd Gen AMD Ryzen Threadripper processors
IBM Power System AC922
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Microsoft Windows
SUSE Linux Enterprise Server 15 SP3 LTSS
Server Applications Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Fedora
Windows Server
libtpms
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libtpms-debuginfo
libtpms-devel
libtpms
libtpms-debugsource
libtpms0-debuginfo
libtpms0
libtpms (Red Hat package)
libtpms0 (Ubuntu package)
libtpms-doc
PowerVM Hypervisor
PowerProtect DP Series Appliance (IDPA)
Dell EMC VxRail Appliance

How to mitigate CVE-2023-1017

Install updates from vendor's website.

Trusted Platform Module (TPM) 2.0 - addressed in versions 1.16, 1.38, 1.59
libtpms - addressed in versions 0.8.9, 0.9.6
Red Hat OpenShift Container Platform - update to 4.13.2
PowerVM Hypervisor - addressed in versions FW1010.60, FW1020.40
IBM Power System AC922 - update to OP940.70
libtpms-debuginfo - update to 0.7.3-8
libtpms-devel - update to 0.7.3-8
libtpms - update to 0.7.3-8
libtpms-debugsource - update to 0.7.3-8
libtpms-devel - update to 0.8.2-150300.3.9.1
libtpms0-debuginfo - update to 0.8.2-150300.3.9.1
libtpms-debugsource - update to 0.8.2-150300.3.9.1
libtpms0 - update to 0.8.2-150300.3.9.1
libtpms (Red Hat package) - update to 0.9.1-3.20211126git1ff6fe1f43.el9_2
libtpms0 (Ubuntu package) - addressed in versions 0.9.3-0ubuntu1.22.04.1, 0.9.3-0ubuntu1.22.10.1
libtpms - addressed in versions 0.9.6-1.fc36, 0.9.6-1.fc37, 0.9.6-1.fc38
libtpms - update to 0.10.0-1
libtpms-devel - update to 0.10.0-1
libtpms-doc - update to 0.10.0-1
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
Dell EMC VxRail Appliance - update to 8.0.101

External References

Related Security Bulletins