In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM reservation for seal/unseal The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM for seal and unseal operations") was correct on the mailing list: https://lore.kernel.org/linux-integrity/[email protected]/ But somehow got rebased so that the tpm_try_get_ops() in tpm2_seal_trusted() got lost. This causes an imbalanced put of the TPM ops and causes oopses on TIS based hardware. This fix puts back the lost tpm_try_get_ops()
Update Linux/Linux to bf84ef2dd2ccdcd8f2658476d34b51455f970ce4; Linux/Linux to 5.10.33 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanKEYS: trusted: Fix TPM reservation for seal/unseal affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM reservation for seal/unseal The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM for seal and unseal operations") was correct on the mailing list: https://lore.kernel.org/linux-integrity/[email protected]/ But somehow got rebased so that the tpm_try_get_ops() in tpm2_seal_trusted() got lost. This causes an imbalanced put of the TPM ops and causes oopses on TIS based hardware. This fix puts back the lost tpm_try_get_ops()
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric |
In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM reservation for seal/unseal The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM for seal and unseal operations") was correct on the mailing list: https://lore.kernel.org/linux-integrity/[email protected]/ But somehow got rebased so that the tpm_try_get_ops() in tpm2_seal_trusted() got lost. This causes an imbalanced put of the TPM ops and causes oopses on TIS based hardware. This fix puts back the lost tpm_try_get_ops()
Update Linux/Linux to bf84ef2dd2ccdcd8f2658476d34b51455f970ce4; Linux/Linux to 5.10.33 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanKEYS: trusted: Fix TPM reservation for seal/unseal affects Linux/Linux (generic), Linux/Linux (generic). Severity is high. In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM reservation for seal/unseal The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM for seal and unseal operations") was correct on the mailing list: https://lore.kernel.org/linux-integrity/[email protected]/ But somehow got rebased so that the tpm_try_get_ops() in tpm2_seal_trusted() got lost. This causes an imbalanced put of the TPM ops and causes oopses on TIS based hardware. This fix puts back the lost tpm_try_get_ops()
AI coding agents often install or upgrade packages automatically in generic. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric |
| >=67118bb78d72aab5b831f054a74ae856339a1974 <bf84ef2dd2ccdcd8f2658476d34b51455f970ce4 || >=498b8fc1cdc13b57b02dd28544b18323900fae10 <39c8d760d44cb3fa0d67e8cd505df81cf4d80999 || >=8c657a0590de585b1115847c17b34a58025f2f4b <9d5171eab462a63e2fbebfccf6026e92be018f20 |
| bf84ef2dd2ccdcd8f2658476d34b51455f970ce4, 39c8d760d44cb3fa0d67e8cd505df81cf4d80999, 9d5171eab462a63e2fbebfccf6026e92be018f20 |
| Linux/Linuxgeneric | >=5.10.20 <5.10.33 || >=5.11.3 <5.11.17 | 5.10.33, 5.11.17 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=67118bb78d72aab5b831f054a74ae856339a1974 <bf84ef2dd2ccdcd8f2658476d34b51455f970ce4 || >=498b8fc1cdc13b57b02dd28544b18323900fae10 <39c8d760d44cb3fa0d67e8cd505df81cf4d80999 || >=8c657a0590de585b1115847c17b34a58025f2f4b <9d5171eab462a63e2fbebfccf6026e92be018f20 |
| bf84ef2dd2ccdcd8f2658476d34b51455f970ce4, 39c8d760d44cb3fa0d67e8cd505df81cf4d80999, 9d5171eab462a63e2fbebfccf6026e92be018f20 |
| Linux/Linuxgeneric | >=5.10.20 <5.10.33 || >=5.11.3 <5.11.17 | 5.10.33, 5.11.17 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by CVE List V5 (cvelist).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard