CVE-2024-36477 (GCVE-0-2024-36477)
Vulnerability from cvelistv5
Published
2024-06-21 11:18
Modified
2026-08-05 11:31
Summary
In the Linux kernel, the following vulnerability has been resolved: tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer The TPM SPI transfer mechanism uses MAX_SPI_FRAMESIZE for computing the maximum transfer length and the size of the transfer buffer. As such, it does not account for the 4 bytes of header that prepends the SPI data frame. This can result in out-of-bounds accesses and was confirmed with KASAN. Introduce SPI_HDRSIZE to account for the header and use to allocate the transfer buffer.
Impacted products
Vendor Product Version
Linux Linux Version: a86a42ac2bd652fdc7836a9d880c306a2485c142
Version: a86a42ac2bd652fdc7836a9d880c306a2485c142
Version: a86a42ac2bd652fdc7836a9d880c306a2485c142
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-36477",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-06-21T13:25:38.377073Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-21T13:25:50.272Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T03:37:05.216Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/1547183852dcdfcc25878db7dd3620509217b0cd"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/de13c56f99477b56980c7e00b09c776d16b7563d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/195aba96b854dd664768f382cd1db375d8181f88"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/char/tpm/tpm_tis_spi_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "1547183852dcdfcc25878db7dd3620509217b0cd",
              "status": "affected",
              "version": "a86a42ac2bd652fdc7836a9d880c306a2485c142",
              "versionType": "git"
            },
            {
              "lessThan": "de13c56f99477b56980c7e00b09c776d16b7563d",
              "status": "affected",
              "version": "a86a42ac2bd652fdc7836a9d880c306a2485c142",
              "versionType": "git"
            },
            {
              "lessThan": "195aba96b854dd664768f382cd1db375d8181f88",
              "status": "affected",
              "version": "a86a42ac2bd652fdc7836a9d880c306a2485c142",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/char/tpm/tpm_tis_spi_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "lessThan": "6.6",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.33",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.9.*",
              "status": "unaffected",
              "version": "6.9.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.10",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.33",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9.4",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10",
                  "versionStartIncluding": "6.6",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer\n\nThe TPM SPI transfer mechanism uses MAX_SPI_FRAMESIZE for computing the\nmaximum transfer length and the size of the transfer buffer. As such, it\ndoes not account for the 4 bytes of header that prepends the SPI data\nframe. This can result in out-of-bounds accesses and was confirmed with\nKASAN.\n\nIntroduce SPI_HDRSIZE to account for the header and use to allocate the\ntransfer buffer."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is reached only through local interfaces \u2014 the `add_key()`/`keyctl` trusted-key path, the `/dev/tpm0` and `/dev/tpmrm0` character devices, or IMA measurement of locally executed files. There is no network-facing consumer of the TPM SPI transfer path, and no physical access to the device is needed since the SPI bus is driven entirely by kernel code on behalf of local requests.\nAC:L - On an affected system (TPM attached to any `SPI_CONTROLLER_HALF_DUPLEX` controller such as Tegra QSPI, AMD, Qualcomm QSPI or TI QSPI), the overflow fires deterministically on every transfer where `transfer_len` reaches `MAX_SPI_FRAMESIZE`, i.e. any TPM command or response body of 64 bytes or more. The attacker simply issues a normal, over-sized TPM command and needs no race, no specific memory layout and no uncontrollable precondition.\nPR:L - An unprivileged local user can trigger the overflow with no capabilities at all by adding a TPM-backed trusted key (`tpm2_seal_trusted()` emits a `TPM2_CC_CREATE` command well over 64 bytes containing user-supplied key material), and on many distributions `/dev/tpmrm0` is additionally accessible to non-root accounts. No root or `CAP_SYS_ADMIN` is required.\nUI:N - The attacker triggers the out-of-bounds access entirely through their own syscalls; no victim needs to open a file, mount a filesystem, or perform any other action. Exploitation is fully self-contained.\nS:U - The corruption occurs in kernel slab memory and its impact is confined to the kernel\u0027s own security authority. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The receive path sets `rx_buf = \u0026phy-\u003eiobuf[4]` for a 64-byte transfer and then copies those bytes back to the caller, producing an out-of-bounds slab read whose contents are returned to userspace in the TPM response. More broadly, the controlled adjacent-object heap corruption can be leveraged to disclose kernel memory, so High is the defensible rating.\nI:H - `memcpy(\u0026phy-\u003eiobuf[4], out, transfer_len)` is a slab out-of-bounds write of four fully attacker-controlled bytes past a 64-byte `devm_kmalloc()` allocation, which on arm64 lands squarely inside the neighbouring kmalloc-192 object. A repeatable, content-controlled write at a fixed offset into a long-lived adjacent kernel object is a classic primitive for corrupting kernel state and escalating privileges.\nA:H - Overwriting four bytes of an adjacent slab object corrupts unrelated kernel structures and readily produces oopses or panics \u2014 the condition was originally caught as a KASAN slab-out-of-bounds report. The overflow can be triggered repeatedly at will, making sustained denial of service trivial."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:31:46.847Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/1547183852dcdfcc25878db7dd3620509217b0cd"
        },
        {
          "url": "https://git.kernel.org/stable/c/de13c56f99477b56980c7e00b09c776d16b7563d"
        },
        {
          "url": "https://git.kernel.org/stable/c/195aba96b854dd664768f382cd1db375d8181f88"
        }
      ],
      "title": "tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-36477",
    "datePublished": "2024-06-21T11:18:46.822Z",
    "dateReserved": "2024-06-21T11:16:40.603Z",
    "dateUpdated": "2026-08-05T11:31:46.847Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/1547183852dcdfcc25878db7dd3620509217b0cd\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/de13c56f99477b56980c7e00b09c776d16b7563d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/195aba96b854dd664768f382cd1db375d8181f88\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T03:37:05.216Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-36477\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-06-21T13:25:38.377073Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-21T13:25:44.841Z\"}}], \"cna\": {\"title\": \"tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerable code is reached only through local interfaces \\u2014 the `add_key()`/`keyctl` trusted-key path, the `/dev/tpm0` and `/dev/tpmrm0` character devices, or IMA measurement of locally executed files. There is no network-facing consumer of the TPM SPI transfer path, and no physical access to the device is needed since the SPI bus is driven entirely by kernel code on behalf of local requests.\\nAC:L - On an affected system (TPM attached to any `SPI_CONTROLLER_HALF_DUPLEX` controller such as Tegra QSPI, AMD, Qualcomm QSPI or TI QSPI), the overflow fires deterministically on every transfer where `transfer_len` reaches `MAX_SPI_FRAMESIZE`, i.e. any TPM command or response body of 64 bytes or more. The attacker simply issues a normal, over-sized TPM command and needs no race, no specific memory layout and no uncontrollable precondition.\\nPR:L - An unprivileged local user can trigger the overflow with no capabilities at all by adding a TPM-backed trusted key (`tpm2_seal_trusted()` emits a `TPM2_CC_CREATE` command well over 64 bytes containing user-supplied key material), and on many distributions `/dev/tpmrm0` is additionally accessible to non-root accounts. No root or `CAP_SYS_ADMIN` is required.\\nUI:N - The attacker triggers the out-of-bounds access entirely through their own syscalls; no victim needs to open a file, mount a filesystem, or perform any other action. Exploitation is fully self-contained.\\nS:U - The corruption occurs in kernel slab memory and its impact is confined to the kernel\u0027s own security authority. No hypervisor, IOMMU, or sandbox boundary is crossed.\\nC:H - The receive path sets `rx_buf = \u0026phy-\u003eiobuf[4]` for a 64-byte transfer and then copies those bytes back to the caller, producing an out-of-bounds slab read whose contents are returned to userspace in the TPM response. More broadly, the controlled adjacent-object heap corruption can be leveraged to disclose kernel memory, so High is the defensible rating.\\nI:H - `memcpy(\u0026phy-\u003eiobuf[4], out, transfer_len)` is a slab out-of-bounds write of four fully attacker-controlled bytes past a 64-byte `devm_kmalloc()` allocation, which on arm64 lands squarely inside the neighbouring kmalloc-192 object. A repeatable, content-controlled write at a fixed offset into a long-lived adjacent kernel object is a classic primitive for corrupting kernel state and escalating privileges.\\nA:H - Overwriting four bytes of an adjacent slab object corrupts unrelated kernel structures and readily produces oopses or panics \\u2014 the condition was originally caught as a KASAN slab-out-of-bounds report. The overflow can be triggered repeatedly at will, making sustained denial of service trivial.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"a86a42ac2bd652fdc7836a9d880c306a2485c142\", \"lessThan\": \"1547183852dcdfcc25878db7dd3620509217b0cd\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a86a42ac2bd652fdc7836a9d880c306a2485c142\", \"lessThan\": \"de13c56f99477b56980c7e00b09c776d16b7563d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"a86a42ac2bd652fdc7836a9d880c306a2485c142\", \"lessThan\": \"195aba96b854dd664768f382cd1db375d8181f88\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/char/tpm/tpm_tis_spi_main.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.6\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.6\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.6.33\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9.4\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.9.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/char/tpm/tpm_tis_spi_main.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/1547183852dcdfcc25878db7dd3620509217b0cd\"}, {\"url\": \"https://git.kernel.org/stable/c/de13c56f99477b56980c7e00b09c776d16b7563d\"}, {\"url\": \"https://git.kernel.org/stable/c/195aba96b854dd664768f382cd1db375d8181f88\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\ntpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer\\n\\nThe TPM SPI transfer mechanism uses MAX_SPI_FRAMESIZE for computing the\\nmaximum transfer length and the size of the transfer buffer. As such, it\\ndoes not account for the 4 bytes of header that prepends the SPI data\\nframe. This can result in out-of-bounds accesses and was confirmed with\\nKASAN.\\n\\nIntroduce SPI_HDRSIZE to account for the header and use to allocate the\\ntransfer buffer.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.33\", \"versionStartIncluding\": \"6.6\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9.4\", \"versionStartIncluding\": \"6.6\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10\", \"versionStartIncluding\": \"6.6\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:31:46.847Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-36477\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:31:46.847Z\", \"dateReserved\": \"2024-06-21T11:16:40.603Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-06-21T11:18:46.822Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…