{"id":"CVE-2024-29038","summary":"tpm2 does not detect if quote was not generated by TPM","details":"tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate arbitrary quote data which is not detected by `tpm2 checkquote`. This issue was patched in version 5.7.","aliases":["GHSA-5495-c38w-gr6f"],"modified":"2026-08-12T03:51:28.627678883Z","published":"2024-06-28T13:44:07.035Z","related":["ALSA-2024:9424","SUSE-SU-2024:1636-1","SUSE-SU-2024:1636-2","SUSE-SU-2025:20151-1","openSUSE-SU-2024:13926-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-1283","CWE-1390"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29038.json"},"references":[{"type":"WEB","url":"https://github.com/tpm2-software/tpm2-tools/releases/tag/5.7"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFR7SVEWCOXORHPCLLGXEMHFMIGG2MFE/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GI4JFEZBKQQUPJ4RWK6IHEWXAFCEJDPI/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29038.json"},{"type":"ADVISORY","url":"https://github.com/tpm2-software/tpm2-tools/security/advisories/GHSA-5495-c38w-gr6f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29038"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tpm2-software/tpm2-tools","events":[{"introduced":"76a880355c905ddb1a48621b1f92ab6405bf2db1"},{"fixed":"c6e182cf690ca0022b77fe7d3c174659917a7e7e"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"4.1-rc0"},{"fixed":"5.7"}]}}],"versions":["5.7-rc1","5.7-rc0","5.4","5.5","5.6","ajay-kish-pub","5.6-rc0","5.5-rc1","5.5-rc0","5.4-rc0","5.3","5.3-rc1","5.3-rc0","5.2","5.2-rc0","5.1","5.1-rc1","5.1-rc0","5.0","5.0-rc0","4.2","4.2-rc1","4.2-RC0","4.1.1-RC1","4.1.1-RC0","4.1","4.1-rc1","4.1-rc0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-29038.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"}]}