CVE Vulnerabilities

CVE-2021-38576

Published: Jan 03, 2022 | Modified: Jan 13, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

Affected Software

Name Vendor Start Version End Version
Edk2 Tianocore 201808 (including) 201808 (including)
Edk2 Tianocore 201811 (including) 201811 (including)
Edk2 Tianocore 201903 (including) 201903 (including)
Edk2 Tianocore 201905 (including) 201905 (including)
Edk2 Tianocore 201908 (including) 201908 (including)
Edk2 Tianocore 201911 (including) 201911 (including)
Edk2 Tianocore 202002 (including) 202002 (including)
Edk2 Tianocore 202005 (including) 202005 (including)
Edk2 Tianocore 202008 (including) 202008 (including)
Edk2 Tianocore 202011 (including) 202011 (including)
Edk2 Tianocore 202102 (including) 202102 (including)
Edk2 Tianocore 202105 (including) 202105 (including)

References