[RHSA-2022:8100-01] Low: swtpm security and bug fix update

Security announcements for all Red Hat products and services. rhsa-announce at redhat.com
Tue Nov 15 12:55:58 UTC 2022


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Low: swtpm security and bug fix update
Advisory ID:       RHSA-2022:8100-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:8100
Issue date:        2022-11-15
CVE Names:         CVE-2022-23645 
=====================================================================

1. Summary:

An update for swtpm is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact
of Low. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AppStream (v. 9) - aarch64, s390x, x86_64

3. Description:

SWTPM is a TPM emulator built on libtpms providing TPM functionality for
QEMU VMs.

Security Fix(es):

* swtpm: Unchecked header size indicator against expected size
(CVE-2022-23645)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 9.1 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

2056491 - CVE-2022-23645 swtpm: Unchecked header size indicator against expected size
2090219 - Not able to install windows 11 OS with vTPM in spec (disable FIPS)

6. Package List:

Red Hat Enterprise Linux AppStream (v. 9):

Source:
swtpm-0.7.0-3.20211109gitb79fd91.el9.src.rpm

aarch64:
swtpm-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm
swtpm-debuginfo-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm
swtpm-debugsource-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm
swtpm-libs-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm
swtpm-libs-debuginfo-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm
swtpm-tools-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm
swtpm-tools-debuginfo-0.7.0-3.20211109gitb79fd91.el9.aarch64.rpm

s390x:
swtpm-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm
swtpm-debuginfo-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm
swtpm-debugsource-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm
swtpm-libs-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm
swtpm-libs-debuginfo-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm
swtpm-tools-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm
swtpm-tools-debuginfo-0.7.0-3.20211109gitb79fd91.el9.s390x.rpm

x86_64:
swtpm-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm
swtpm-debuginfo-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm
swtpm-debugsource-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm
swtpm-libs-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm
swtpm-libs-debuginfo-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm
swtpm-tools-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm
swtpm-tools-debuginfo-0.7.0-3.20211109gitb79fd91.el9.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2022-23645
https://access.redhat.com/security/updates/classification/#low
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.1_release_notes/index

8. Contact:

The Red Hat security contact is <secalert at redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBY3OMXtzjgjWX9erEAQgHDA/+OMR2sFGbdP6hED6vJ/mp7wcx8xDO2fcl
lUsbNs1WXDZ8N0ZFoQNN/iqXOE4f3YtliWHcFQOcacIyTAyev8469r4lTRHK5+RV
KcQOOvdvVeibxvjR1bQS5hMZET+FWxfcQawVkTZjse6Osef6I3GF7VD5QoSbDI2B
Lgj9SdvshnG2goTyLpwE9ZFUIyUhWy1CVDEGOFoeLk1zkJFMerkWb/FeQa2yCOxZ
hPx1d3NIOH6V+bYYRl1owf9SpS/DhQJ7sCsay3zwz8uzjqzSX3x2cnj1U1LgCQ66
RkP3T1CHY9uRd3T7WT0oAGj4uodtXjf8+64ZgNBKqtv/2Ls7aZciIvRb1xwNVGc2
fOTSdv3zRPBwoIlxRiCxuqr5kDj3+9b9rGu1xqkedEt+736XaBcQ6uD6gHjFS41R
2KWxQ/Db0DetUyZc99atVs9YcP5YPqI+XbQWNJaGPmLR3JaZ8JAQTNEQWAKMXQD/
EPnoPYY8sgmZGDnzZb04IcnYIfvzj3DLWm0JB3cORwawvL1SulFhoikEuJ9DEKPG
uIhE1nwHfGUlMmIMAbk0dPzoDt80gZMr4nHlWfEUOwCUQrQw6O67Nr9JNd32bwAW
T77tKs+HriSXYQ9isoaGFnlVsVH965tEte1pHna3YqNznR3GC6Hh072gfJXWf/qx
XpYcV7g6aB0=
=l7Di
-----END PGP SIGNATURE-----


More information about the RHSA-announce mailing list