tpm2: Marshal event sequence objects' hash state ---- Build of libtpms 0.8.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-c4edcdbf1c 2021-09-24 20:04:10.616639 --------------------------------------------------------------------------------Name : libtpms Product : Fedora 35 Version : 0.8.6 Release : 0.20210910git7a4d46a119.fc35.0 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. --------------------------------------------------------------------------------Update Information: tpm2: Marshal event sequence objects' hash state ---- Build of libtpms 0.8.5 --------------------------------------------------------------------------------ChangeLog: * Fri Sep 10 2021 Stefan Berger - 0.8.6-1.20210910git7a4d46a119 - tpm2: Marshal event sequence objects' hash state * Wed Sep 1 2021 Stefan Berger - 0.8.5-1.20210901git18ba4c0206 - Build of libtpms 0.8.5 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c4edcdbf1c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A bug in TCG TPM2 Software Stack may result in information disclosure to a local attacker.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: TCG TPM2 Software Stack: Information disclosure Date: July 07, 2021 Bugs: #746563 ID: 202107-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A bug in TCG TPM2 Software Stack may result in information disclosure to a local attacker. Background ========= TCG TPM2 Software Stack is a library to interface with trusted platform modules. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-crypt/tpm2-tss < 2.4.3 > = 2.4.3 Description ========== TCG TPM2 Software Stack did not appropriately apply FAPI policies to protect data encrypted with the trusted platform module. Impact ===== Data encrypted using TCG TPM2 Software Stack (tpm2-tss) may not be protected from an attacker. Workaround ========= There is no known workaround at this time. Resolution ========= All tpm2-tss users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-crypt/tpm2-tss-2.4.3" References ========= [ 1 ] CVE-2020-24455 https://nvd.nist.gov/vuln/detail/CVE-2020-24455 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentialityand security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-caf9e04ef1 2021-03-10 00:41:43.224986 --------------------------------------------------------------------------------Name : libtpms Product : Fedora 33 Version : 0.7.7 Release : 0.20210302gitfd5bd3fb1d.fc33 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. --------------------------------------------------------------------------------Update Information: tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue --------------------------------------------------------------------------------ChangeLog: * Tue Mar 2 2021 Stefan Breger - 0.7.7-0.20210302gitfd5bd3fb1d - tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue - tpm2: fixes a suspend/resume problem when public keys are loaded --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-caf9e04ef1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.