Database/Firmware, BMC & network fabric
Intel PTT / fTPM (ECDSA and ECSchnorr timing): The firmware TPM's signing operation leaks nonce information through
Impact
The firmware TPM's signing operation leaks nonce information through timing, letting an attacker recover the private key after observing a few hundred signatures. Intel PTT is the TPM on a large share of server boards where nobody fitted a discrete chip - so this is the default configuration, not an edge case. Recovered attestation keys let an attacker sign forged quotes and make a compromised node present as measured-clean.
Who can reach it
Local unprivileged user who can request signatures, or a network attacker where the TPM key backs a network-facing service such as a VPN or TLS client certificate. No physical access needed, which is what separated this from earlier TPM side channels.
What to do
Intel CSME/PTT firmware update, delivered as a BIOS/ME package from the server OEM - per-node flash and reboot. Regenerate and re-enroll every key the fTPM signed with, because the firmware fix does not un-leak an already-extracted key. If attestation is load-bearing for your product, this is the argument for a discrete TPM over the chipset one.
References
Related entries
- Linux bnxt_re RoCE driver (bnxt_re_create_srq memory leak): A tenant can exhaust host memory by repeatedly triggeringCVE-2019-19077 · Linux bnxt_re RoCE driver (bnxt_re_create_srq memory leak)Medium
- Intel processors (vector register sampling): Stale values left in vector registers can be sampled by other contextsCVE-2020-0548 · Intel processors (vector register sampling)Medium
- Intel processors (L1D eviction sampling) / SGX attestation keys: Stale data can be sampled out of L1D fill buffersCVE-2020-0549 · Intel processors (L1D eviction sampling) / SGX attestation keysMedium
- AMD EPYC SEV-ES / SEV-SNP - information disclosure: An information-disclosure flaw in SEV-ES and SEV-SNP on EPYC lets aCVE-2020-12966 · AMD EPYC SEV-ES / SEV-SNP - information disclosureMedium
- Intel processors (fast store forwarding predictor): Improper isolation of a shared microarchitectural resource letsCVE-2020-8698 · Intel processors (fast store forwarding predictor)Medium
- Intel processors (fast store forwarding predictor initialisation): Improper initialisation of a shared predictorCVE-2021-0145 · Intel processors (fast store forwarding predictor initialisation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.