Oval Definition:oval:org.opensuse.security:def:202322745
Revision Date:2023-06-22Version:1
Title:CVE-2023-22745
Description:

tpm2-tss is an open source software implementation of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2 Software Stack (TSS2). In affected versions `Tss2_RC_SetHandler` and `Tss2_RC_Decode` both index into `layer_handler` with an 8 bit layer number, but the array only has `TPM2_ERROR_TSS2_RC_LAYER_COUNT` entries, so trying to add a handler for higher-numbered layers or decode a response code with such a layer number reads/writes past the end of the buffer. This Buffer overrun, could result in arbitrary code execution. An example attack would be a MiTM bus attack that returns 0xFFFFFFFF for the RC. Given the common use case of TPM modules an attacker must have local access to the target machine with local system privileges which allows access to the TPM system. Usually TPM access requires administrative privilege.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2023-22745
SUSE CVE-2023-22745
SUSE-SU-2023:0526-1
SUSE-SU-2023:0613-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.3 is installed
  • AND Package Information
  • libtss2-esys0 is affected
  • OR libtss2-fapi1 is affected
  • OR libtss2-mu0 is affected
  • OR libtss2-rc0 is affected
  • OR libtss2-sys1 is affected
  • OR libtss2-tcti-device0 is affected
  • OR libtss2-tctildr0 is affected
  • OR tpm2-0-tss is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND Package Information
  • libtss2-esys0-3.1.0-150400.3.3.1 is installed
  • OR libtss2-fapi1-3.1.0-150400.3.3.1 is installed
  • OR libtss2-mu0-3.1.0-150400.3.3.1 is installed
  • OR libtss2-rc0-3.1.0-150400.3.3.1 is installed
  • OR libtss2-sys1-3.1.0-150400.3.3.1 is installed
  • OR libtss2-tcti-cmd0-3.1.0-150400.3.3.1 is installed
  • OR libtss2-tcti-device0-3.1.0-150400.3.3.1 is installed
  • OR libtss2-tcti-mssim0-3.1.0-150400.3.3.1 is installed
  • OR libtss2-tcti-pcap0-3.1.0-150400.3.3.1 is installed
  • OR libtss2-tcti-swtpm0-3.1.0-150400.3.3.1 is installed
  • OR libtss2-tctildr0-3.1.0-150400.3.3.1 is installed
  • OR tpm2-0-tss-3.1.0-150400.3.3.1 is installed
  • OR tpm2-0-tss-devel-3.1.0-150400.3.3.1 is installed
  • BACK