Executive brief
A vulnerability in the Linux kernel's Trusted Platform Module (TPM) driver could allow a local user to cause a denial-of-service condition. The TPM is a hardware component used for secure operations like disk encryption and identity verification. If a specific command fails, the system may fail to clean up internal resources, potentially leading to a system crash or exhaustion of security hardware resources.
Technical details
A resource management flaw exists in the Linux kernel's TPM driver (drivers/char/tpm). The function tpm_dev_transmit prepares the TPM space for command execution but lacks a rollback mechanism if the command fails. This results in the leakage of transient handles when the device is closed without subsequent successful commands. An attacker with local access could exploit this incomplete cleanup (CWE-459) to exhaust TPM resources, leading to a denial-of-service (DoS) condition. The issue has been resolved by ensuring tpm2_flush_space is called upon transmission failure.
Affected products
- Linux Linux Kernel 4.12 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.112, 6.2 to 6.6.53, 6.7 to 6.10.12, 6.11 to 6.11.1
Timeline
- 2024-10-21: advisory: Initial disclosure by kernel.org
- 2024-10-21: disclosed
- 2024-10-21: patched
References
- https://git.kernel.org/stable/c/2c9b228938e9266a1065a3f4fe5c99b7235dc439
- https://git.kernel.org/stable/c/3f9f72d843c92fb6f4ff7460d774413cde7f254c
- https://git.kernel.org/stable/c/82478cb8a23bd4f97935bbe60d64528c6d9918b4
- https://git.kernel.org/stable/c/87e8134c18977b566f4ec248c8a147244da69402
- https://git.kernel.org/stable/c/adf4ce162561222338cf2c9a2caa294527f7f721
- https://git.kernel.org/stable/c/c84ceb546f30432fccea4891163f7050f5bee5dd
- https://git.kernel.org/stable/c/e3aaebcbb7c6b403416f442d1de70d437ce313a7