{"id":"UBUNTU-CVE-2021-3569","details":"A stack corruption bug was found in libtpms in versions before 0.7.2 and before 0.8.0 while decrypting data using RSA. This flaw could result in a SIGBUS (bad memory access) and termination of swtpm. The highest threat from this vulnerability is to system availability.","modified":"2025-07-16T07:42:54.874601Z","published":"2021-06-03T12:15:00Z","withdrawn":"2025-07-18T16:46:27Z","upstream":["CVE-2021-3569"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-3569"},{"type":"REPORT","url":"https://github.com/stefanberger/libtpms/commit/505ef841c00b4c096b1977c667cb957bec3a1d8b"},{"type":"REPORT","url":"https://github.com/stefanberger/libtpms/commit/40cfe134c017d3aeaaed05ce71eaf9bfbe556b16"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-3569"}],"affected":[{"package":{"name":"libtpms","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libtpms@0.8.2-1ubuntu1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.2-1ubuntu1"}]}],"ecosystem_specific":{"binaries":[{"binary_name":"libtpms-dev","binary_version":"0.8.2-1ubuntu1"},{"binary_name":"libtpms0","binary_version":"0.8.2-1ubuntu1"},{"binary_name":"libtpms0-dbgsym","binary_version":"0.8.2-1ubuntu1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-3569.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}