Database/Firmware, BMC & network fabric

TPM 2.0 reference implementation: Out-of-bounds read in the same routine — disclosure of TPM-resident data
CVSS 5.5CVE-2023-1018Firmware, BMC & network fabriccurated
Impact
Out-of-bounds read in the same routine — disclosure of TPM-resident data
Who can reach it
Local, low privilege
What to do
Same TPM firmware update and the same key-loss problem
References
Related entries
- TPM 2.0 reference implementation: Out-of-bounds write in `CryptParameterDecryption`CVE-2023-1017 · TPM 2.0 reference implementationHigh
- Intel processors (return predictor target sharing): Return predictor targets are shared non-transparentlyCVE-2023-38575 · Intel processors (return predictor target sharing)Medium
- Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXECVE-2023-40238 · Insyde InsydeH2O BmpDecoderDxeMedium
- shim (verify_buffer_authenticode): Out-of-bounds read on a malformed PE file crashes shim and blocks bootCVE-2023-40549 · shim (verify_buffer_authenticode)Medium
- shim (verify_buffer_sbat): Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attackerCVE-2023-40550 · shim (verify_buffer_sbat)Medium
- Linux kernel (drivers/infiniband/sw/rxe): Soft-RoCE queue-pair cleanup drains send and receive work queues that aCVE-2023-53528 · Linux kernel (drivers/infiniband/sw/rxe)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.