CVE Vulnerabilities

CVE-2020-24455

Missing Initialization of Resource

Published: Feb 26, 2021 | Modified: Nov 07, 2023
CVSS 3.x
6.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
4.1 LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.

Weakness

The product does not initialize a critical resource.

Affected Software

Name Vendor Start Version End Version
Tpm2_software_stack Tpm2_software_stack_project * 2.4.3 (excluding)
Tpm2_software_stack Tpm2_software_stack_project 3.0.0 (including) 3.0.1 (excluding)
Tpm2-tss Ubuntu trusty *
Tpm2-tss Ubuntu upstream *

Potential Mitigations

References