ALAS-2024-703


Amazon Linux 2023 Security Advisory: ALAS-2024-703
Advisory Release Date: 2024-08-14 19:14 Pacific
Advisory Updated Date: 2024-08-19 10:50 Pacific
Severity: Medium

Issue Overview:

tpm2-tss: arbitrary quote data may go undetected by Fapi_VerifyQuote (CVE-2024-29040)


Affected Packages:

tpm2-tss


Issue Correction:
Run dnf update tpm2-tss --releasever 2023.5.20240819 to update your system.

New Packages:
aarch64:
    tpm2-tss-fapi-4.0.2-1.amzn2023.aarch64
    tpm2-tss-fapi-debuginfo-4.0.2-1.amzn2023.aarch64
    tpm2-tss-debuginfo-4.0.2-1.amzn2023.aarch64
    tpm2-tss-debugsource-4.0.2-1.amzn2023.aarch64
    tpm2-tss-4.0.2-1.amzn2023.aarch64
    tpm2-tss-devel-4.0.2-1.amzn2023.aarch64

src:
    tpm2-tss-4.0.2-1.amzn2023.src

x86_64:
    tpm2-tss-fapi-debuginfo-4.0.2-1.amzn2023.x86_64
    tpm2-tss-debuginfo-4.0.2-1.amzn2023.x86_64
    tpm2-tss-fapi-4.0.2-1.amzn2023.x86_64
    tpm2-tss-4.0.2-1.amzn2023.x86_64
    tpm2-tss-debugsource-4.0.2-1.amzn2023.x86_64
    tpm2-tss-devel-4.0.2-1.amzn2023.x86_64