blob: 3415dc6f2f4cab192015d3d49fcb56327fc4a9bb [file] [log] [blame]
modules:
- module: github.com/google/go-tpm
versions:
- fixed: 0.3.0
packages:
- package: github.com/google/go-tpm/tpm
symbols:
- CreateWrapKey
description: |
Due to repeated usage of a XOR key an attacker that can eavesdrop on the TPM 1.2 transport
is able to calculate usageAuth for keys created using CreateWrapKey, despite it being encrypted,
allowing them to use the created key.
published: 2021-04-14T20:04:52Z
cves:
- CVE-2020-8918
ghsas:
- GHSA-5x29-3hr9-6wpw
credit: Chris Fenner
references:
- fix: https://github.com/google/go-tpm/pull/195
- fix: https://github.com/google/go-tpm/commit/d7806cce857a1a020190c03348e5361725d8f141