CVE-2021-3569

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
03/06/2021
Last modified:
07/10/2022

Description

A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libtpms_project:libtpms:*:*:*:*:*:*:*:* 0.7.2 (excluding)
cpe:2.3:a:libtpms_project:libtpms:*:*:*:*:*:*:*:* 0.7.3 (including) 0.8.0 (excluding)
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*


References to Advisories, Solutions, and Tools