RSA key weakening via truncated prime mask
Published Apr 19, 2021 · Updated Aug 3, 2024
Insufficient entropy in libtpms before 0.8.0 allows local users to weaken TPM 2 RSA key confidentiality through predictable prime bits. On 64-bit systems, RsaAdjustPrimeCandidate() shifts the word mask by RADIX_BITS minus 16, retaining 16 low bits instead of 48 and forcing 32 prime bits to zero. Access to a TPM 2 instance using the affected algorithm is required; the defect reduces 2048-bit RSA strength to roughly 1984 bits without altering data or interrupting service.
Summary
What happened
Insufficient entropy in libtpms before 0.8.0 allows local users to weaken TPM 2 RSA key confidentiality through predictable prime bits. On 64-bit systems, RsaAdjustPrimeCandidate() shifts the word mask by RADIX_BITS minus 16, retaining 16 low bits instead of 48 and forcing 32 prime bits to zero. Access to a TPM 2 instance using the affected algorithm is required; the defect reduces 2048-bit RSA strength to roughly 1984 bits without altering data or interrupting service.
The record
- CVE
- CVE-2021-3505
- Published
- Apr 19, 2021
- Updated
- Aug 3, 2024
- Vendor
- libtpms Project
- Product
- libtpms
- Classifications
- CWE-331
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Apr 19, 2021CVE publishedPublication date reported by the CVE source.
- Aug 3, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=libtpms 0.8.0
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- TPM2_CreatePrimary predictable-prime reproductionproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo