Ubuntu Security Notice 5933-1 - Francisco Falcon discovered that Libtpms did not properly manage memory when performing certain cryptographic operations. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. It was discovered that Libtpms did not properly manage memory when handling certain commands. An attacker could possibly use this issue to cause a denial of service.
6fc24e5484e696cf3ba998861e7fbb3b38c4c21b77a94ea189a3dc50f39c039a
==========================================================================
Ubuntu Security Notice USN-5933-1
March 07, 2023
libtpms vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.10
- Ubuntu 22.04 LTS
Summary:
Several security issues were fixed in Libtpms.
Software Description:
- libtpms: TPM emulation library
Details:
Francisco Falcon discovered that Libtpms did not properly manage memory
when performing certain cryptographic operations. An attacker could
possibly use this issue to cause a denial of service, or possibly execute
arbitrary code. (CVE-2023-1017, CVE-2023-1018)
It was discovered that Libtpms did not properly manage memory when
handling certain commands. An attacker could possibly use this issue
to cause a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.10:
libtpms0 0.9.3-0ubuntu1.22.10.1
Ubuntu 22.04 LTS:
libtpms0 0.9.3-0ubuntu1.22.04.1
After a standard system update you need to restart any application
using Libtpms libraries to make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5933-1
CVE-2023-1017, CVE-2023-1018, https://launchpad.net/bugs/2009608
Package Information:
https://launchpad.net/ubuntu/+source/libtpms/0.9.3-0ubuntu1.22.10.1
https://launchpad.net/ubuntu/+source/libtpms/0.9.3-0ubuntu1.22.04.1