Database/Firmware, BMC & network fabric

TPM 2.0 reference implementation: Out-of-bounds write in `CryptParameterDecryption`
CVE-2023-1017Firmware, BMC & network fabriccurated
Impact
Out-of-bounds write in CryptParameterDecryption — code execution inside the TPM or a bricked TPM. If the TPM is the root of trust for attestation, a compromised TPM invalidates every measured-boot claim the cloud makes to its tenants
Who can reach it
Local, low privilege
What to do
TPM firmware update from the TPM/platform vendor; TPM firmware updates frequently clear the TPM, which invalidates sealed keys and any disk encryption bound to PCRs — this is why fleets skip it
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.