SUSE-SU-2017:3090-1

    Dashboard / Vulnerabilities / SUSE-SU-2017:3090-1

    SUSE-SU-2017:3090-1

    Published: 24 Nov 2017Last Modified: 4 Feb 2026
    Upstream:

    Summary: Recommended update for tboot

    Details: This update for tboot fixes the following issues: Security issue fixed: - CVE-2017-16837: Certain function pointers in Trusted Boot (tboot) through 1.9.6 are notvalidated and can cause arbitrary code execution, which allows local users tooverwrite dynamic PCRs of Trusted Platform Module (TPM) by h (bsc#1068390) Bug fixes: - Fixed failed trusted boot on some systems like Intel Xeon 'Purley 8s' processors. The following error message showed: 'TBOOT: wait-for-sipi loop timed-out'. Booting continued but 'TXT measured launch' was wrongly reported as FALSE. (bsc#1057555)

    Affected packages

    Package

    Name: tboot

    Purl: pkg:rpm/suse/tboot&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -20160518_1.9.4-7.5.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High