|
|
Subscribe / Log in / New account

Red Hat alert RHSA-2022:8100-01 (swtpm)

From:  "Security announcements for all Red Hat products and services." <rhsa-announce@redhat.com>
To:  rhsa-announce@redhat.com
Subject:  [RHSA-2022:8100-01] Low: swtpm security and bug fix update
Date:  Tue, 15 Nov 2022 12:55:58 -0000
Message-ID:  <mailman.7244.1668516959.3012.rhsa-announce@redhat.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Low: swtpm security and bug fix update Advisory ID: RHSA-2022:8100-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8100 Issue date: 2022-11-15 CVE Names: CVE-2022-23645 ===================================================================== 1. Summary: An update for swtpm is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, s390x, x86_64 3. Description: SWTPM is a TPM emulator built on libtpms providing TPM functionality for QEMU VMs. Security Fix(es): * swtpm: Unchecked header size indicator against expected size (CVE-2022-23645) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2056491 - CVE-2022-23645 swtpm: Unchecked header size indicator against expected size 2090219 - Not able to install windows 11 OS with vTPM in spec (disable FIPS) 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: swtpm-0.7.0-3.20211109gitb79fd91.el9.src.rpm aarch64: swtpm-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm swtpm-debuginfo-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm swtpm-debugsource-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm swtpm-libs-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm swtpm-libs-debuginfo-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm swtpm-tools-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm swtpm-tools-debuginfo-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm s390x: swtpm-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm swtpm-debuginfo-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm swtpm-debugsource-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm swtpm-libs-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm swtpm-libs-debuginfo-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm swtpm-tools-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm swtpm-tools-debuginfo-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm x86_64: swtpm-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm swtpm-debuginfo-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm swtpm-debugsource-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm swtpm-libs-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm swtpm-libs-debuginfo-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm swtpm-tools-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm swtpm-tools-debuginfo-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-23645 https://access.redhat.com/security/updates/classification... https://access.redhat.com/documentation/en-us/red_hat_ent... 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY3OMXtzjgjWX9erEAQgHDA/+OMR2sFGbdP6hED6vJ/mp7wcx8xDO2fcl lUsbNs1WXDZ8N0ZFoQNN/iqXOE4f3YtliWHcFQOcacIyTAyev8469r4lTRHK5+RV KcQOOvdvVeibxvjR1bQS5hMZET+FWxfcQawVkTZjse6Osef6I3GF7VD5QoSbDI2B Lgj9SdvshnG2goTyLpwE9ZFUIyUhWy1CVDEGOFoeLk1zkJFMerkWb/FeQa2yCOxZ hPx1d3NIOH6V+bYYRl1owf9SpS/DhQJ7sCsay3zwz8uzjqzSX3x2cnj1U1LgCQ66 RkP3T1CHY9uRd3T7WT0oAGj4uodtXjf8+64ZgNBKqtv/2Ls7aZciIvRb1xwNVGc2 fOTSdv3zRPBwoIlxRiCxuqr5kDj3+9b9rGu1xqkedEt+736XaBcQ6uD6gHjFS41R 2KWxQ/Db0DetUyZc99atVs9YcP5YPqI+XbQWNJaGPmLR3JaZ8JAQTNEQWAKMXQD/ EPnoPYY8sgmZGDnzZb04IcnYIfvzj3DLWm0JB3cORwawvL1SulFhoikEuJ9DEKPG uIhE1nwHfGUlMmIMAbk0dPzoDt80gZMr4nHlWfEUOwCUQrQw6O67Nr9JNd32bwAW T77tKs+HriSXYQ9isoaGFnlVsVH965tEte1pHna3YqNznR3GC6Hh072gfJXWf/qx XpYcV7g6aB0= =l7Di -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds