• 公告ID (KylinSec-SA-2022-2089)

摘要:

libtpms security update

安全等级: Medium

公告ID: KylinSec-SA-2022-2089

发布日期: 2022年9月23日

关联CVE: CVE-2021-3505  

  • 详细介绍

1. 漏洞描述

   

A library providing TPM functionality for VMs. Targeted for integration into Qemu.

Security Fix(es):

A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3505)

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-3505 KY3.4-4A libtpms Fixed

3. 影响组件

    libtpms

4. 修复版本

   

KY3.4-4A

软件名称 架构 版本号
libtpms x86_64 0.7.3-7.kb1.ky3
libtpms-devel x86_64 0.7.3-7.kb1.ky3
libtpms-devel aarch64 0.7.3-7.kb1.ky3
libtpms aarch64 0.7.3-7.kb1.ky3

5. 修复方法

sudo dnf udpate libtpms

6. 下载链接

   

KY3.4-4A:

x86_64:

     libtpms   

     libtpms-devel   

aarch64:

     libtpms-devel   

     libtpms   

上一篇:KylinSec-SA-2022-2088 下一篇:KylinSec-SA-2022-2090