CVE-2024-29039
NixOS vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2024-29039) affects tpm2-tools, which is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability was discovered in versions prior to 5.7 and allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in the PCR input file. The issue was disclosed in June 2024 and has been patched in version 5.7 (GitHub Advisory, NVD).

Technical details

The vulnerability stems from a missing validation check in the tpm2_checkquote tool. While the tool verifies that the pcrDigest from the quote matches the digest of concatenated PCRs from the PCR input file, it fails to verify that the PCR selection of the PCR input file matches the one included in the quote. This oversight allows attackers to craft PCR input files with arbitrary TPML_PCR_SELECTION values. The vulnerability has been assigned a CVSS v3.1 base score of 9.0 CRITICAL with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H (GitHub Advisory).

Impact

As a result of this vulnerability, digest values can be incorrectly mapped to PCR slots and banks, providing a misleading picture of the TPM state. An attacker can swap a compatible selection for another, causing TPM register values to be associated with the wrong PCR index or bank. The vulnerability also extends to the reinterpretation of data across PCR banks and their corresponding hashing algorithms (GitHub Advisory).

Exploitability

The vulnerability is described as relatively easy to exploit, though less severe than related vulnerabilities. It can be exploited by manipulating the PCR input file, which is treated as untrusted data. The attack requires crafting specific PCR input files that maintain matching digest concatenations while altering the PCR selection information (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in tpm2-tools version 5.7. Users are advised to upgrade to this version or later to address the security issue. The fix includes proper validation of PCR selection data (GitHub Release, Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management