CVE-2022-23645
Last modified
CVE-2022-23645 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Swtpm Project | Swtpm | < 0.5.3 |
| Swtpm Project | Swtpm | >= 0.6.0, < 0.6.2 |
| Swtpm Project | Swtpm | 0.7.0 |
| Redhat | Enterprise Linux | 8.0 |
| Fedoraproject | Fedora | 35 |
References
- https://github.com/stefanberger/swtpm/commit/9f740868fc36761de27df3935513bdebf8852d19Patch, Third Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.5.3Release Notes, Third Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.6.2Release Notes, Third Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.7.1Release Notes, Third Party Advisory
- https://github.com/stefanberger/swtpm/security/advisories/GHSA-2qgm-8xf4-3hqwPatch, Third Party Advisory
- https://github.com/stefanberger/swtpm/commit/9f740868fc36761de27df3935513bdebf8852d19Patch, Third Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.5.3Release Notes, Third Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.6.2Release Notes, Third Party Advisory
- https://github.com/stefanberger/swtpm/releases/tag/v0.7.1Release Notes, Third Party Advisory
- https://github.com/stefanberger/swtpm/security/advisories/GHSA-2qgm-8xf4-3hqwPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23645?
How severe is CVE-2022-23645?
How do I fix CVE-2022-23645?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2364A vulnerability, which was classified as problematic, was fo…5.4
- CVE-2022-23640Excel-Streaming-Reader is an easy-to-use implementation of a…9.8
- CVE-2022-23641Discourse is an open source discussion platform. In versions…6.5
- CVE-2022-23642Sourcegraph is a code search and navigation engine. Sourcegr…8.8
- CVE-2022-23643Sourcegraph is a code search and navigation engine. Sourcegr…6.5
- CVE-2022-23644BookWyrm is a decentralized social network for tracking read…8.8
- CVE-2022-23646Next.js is a React framework. Starting with version 10.0.0 a…7.5
- CVE-2022-23647Prism is a syntax highlighting library. Starting with versio…6.1
- CVE-2022-23648containerd is a container runtime available as a daemon for …7.5
- CVE-2022-23649Cosign provides container signing, verification, and storage…3.3
- CVE-2022-2365Cross-site Scripting (XSS) - Stored in GitHub repository zad…5.4
- CVE-2022-23650Netmaker is a platform for creating and managing virtual ove…8.8
Are you affected by CVE-2022-23645?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
