A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.
2021-06-03T12:15:07.827
2024-11-21T06:21:52.037
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | libtpms_project | libtpms | < 0.7.2 | Yes |
Application | libtpms_project | libtpms | < 0.8.0 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |