CVE Vulnerabilities

CVE-2021-38576

Published: Jan 03, 2022 | Modified: Nov 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

Affected Software

NameVendorStart VersionEnd Version
Edk2Tianocore201808 (including)201808 (including)
Edk2Tianocore201811 (including)201811 (including)
Edk2Tianocore201903 (including)201903 (including)
Edk2Tianocore201905 (including)201905 (including)
Edk2Tianocore201908 (including)201908 (including)
Edk2Tianocore201911 (including)201911 (including)
Edk2Tianocore202002 (including)202002 (including)
Edk2Tianocore202005 (including)202005 (including)
Edk2Tianocore202008 (including)202008 (including)
Edk2Tianocore202011 (including)202011 (including)
Edk2Tianocore202102 (including)202102 (including)
Edk2Tianocore202105 (including)202105 (including)
Edk2Ubuntubionic*
Edk2Ubuntuesm-apps/bionic*
Edk2Ubuntuesm-infra/focal*
Edk2Ubuntufocal*
Edk2Ubuntuhirsute*
Edk2Ubuntuimpish*
Edk2Ubuntutrusty*
Edk2Ubuntuxenial*

References