ALAS-2024-693


Amazon Linux 2023 Security Advisory: ALAS-2024-693
Advisory Release Date: 2024-08-01 04:06 Pacific
Advisory Updated Date: 2024-08-06 15:00 Pacific
Severity: Medium

Issue Overview:

tpm2-tools: arbitrary quote data may go undetected by tpm2_checkquote (CVE-2024-29038)

tpm2-tools: pcr selection value is not compared with the attest (CVE-2024-29039)


Affected Packages:

tpm2-tools


Issue Correction:
Run dnf update tpm2-tools --releasever 2023.5.20240805 to update your system.

New Packages:
aarch64:
    tpm2-tools-debuginfo-5.5-4.amzn2023.0.2.aarch64
    tpm2-tools-debugsource-5.5-4.amzn2023.0.2.aarch64
    tpm2-tools-5.5-4.amzn2023.0.2.aarch64

src:
    tpm2-tools-5.5-4.amzn2023.0.2.src

x86_64:
    tpm2-tools-debuginfo-5.5-4.amzn2023.0.2.x86_64
    tpm2-tools-debugsource-5.5-4.amzn2023.0.2.x86_64
    tpm2-tools-5.5-4.amzn2023.0.2.x86_64