{"id":"MGASA-2024-0170","summary":"Updated tpm2-tools packages fixes security vulnerabilities","details":"A flaw was found in the tpm2-tools package. This issue occurs due to a\nmissing check whether the magic number in attest is equal to\nTPM2_GENERATED_VALUE, which can allow an attacker to generate arbitrary\nquote data that may not be detected by tpm2_checkquote (CVE-2024-29038).\nThe pcr selection which is passed with the --pcr parameter is not\ncompared with the attest. So it is possible to fake a valid attestation\n(CVE-2024-29039).\nA vulnerability classified as problematic was found in tpm2-tools. This\nvulnerability affects an unknown code of the file\ntools/misc/tpm2_checkquote.c of the component pcr Selection Value\nHandler. The manipulation with an unknown input leads to a comparison\nvulnerability. The product compares two entities in a security-relevant\ncontext, but the comparison is incorrect, which may lead to resultant\nweaknesses.\n","modified":"2026-04-16T00:08:52.525415047Z","published":"2024-05-09T02:40:29Z","upstream":["CVE-2024-29038","CVE-2024-29039"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2024-0170.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33175"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2278071"},{"type":"WEB","url":"https://vuldb.com/?id.262756"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2278075"}],"affected":[{"package":{"name":"tpm2-tools","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/tpm2-tools?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.1-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2024-0170.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}