Candidate: CVE-2021-3569 PublicDate: 2021-06-03 12:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3569 https://github.com/stefanberger/libtpms/commit/505ef841c00b4c096b1977c667cb957bec3a1d8b (v0.8.0) https://github.com/stefanberger/libtpms/commit/40cfe134c017d3aeaaed05ce71eaf9bfbe556b16 (v0.7.2) Description: A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_libtpms: upstream_libtpms: released (0.8.2-1) trusty_libtpms: ignored (out of standard support) trusty/esm_libtpms: DNE xenial_libtpms: ignored (out of standard support) bionic_libtpms: DNE focal_libtpms: DNE groovy_libtpms: ignored (reached end-of-life) hirsute_libtpms: ignored (reached end-of-life) impish_libtpms: not-affected (0.8.2-1ubuntu1) jammy_libtpms: not-affected (0.8.2-1ubuntu1) devel_libtpms: not-affected (0.8.2-1ubuntu1)