OESA-2022-1959

    Dashboard / Vulnerabilities / OESA-2022-1959

    OESA-2022-1959

    Published: 23 Sept 2022Last Modified: 18 Aug 2026
    Upstream:

    Summary: libtpms security update

    Details: A library providing TPM functionality for VMs. Targeted for integration into Qemu. Security Fix(es): A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3505)

    Affected packages

    Package

    Name: libtpms

    Purl: pkg:rpm/openEuler/libtpms&distro=openEuler-20.03-LTS-SP1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.7.3-7.oe1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2022-1959 | CVE-DB