GPU VulnDB

Database/Firmware, BMC & network fabric

TPM 2.0 reference implementation: Out-of-bounds write in `CryptParameterDecryption`

CVE-2023-1017Firmware, BMC & network fabriccurated

Impact

Out-of-bounds write in CryptParameterDecryption — code execution inside the TPM or a bricked TPM. If the TPM is the root of trust for attestation, a compromised TPM invalidates every measured-boot claim the cloud makes to its tenants

Who can reach it

Local, low privilege

What to do

TPM firmware update from the TPM/platform vendor; TPM firmware updates frequently clear the TPM, which invalidates sealed keys and any disk encryption bound to PCRs — this is why fleets skip it

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.