« Volver al listado

CVE-2026-46283

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

tpm: Use kfree_sensitive() to free auth session in tpm_dev_release()

tpm_dev_release() uses plain kfree() to free chip->auth, which contains sensitive cryptographic material including HMAC session keys, nonces, and passphrase data (struct tpm2_auth).

Every other code path that frees this structure uses kfree_sensitive() to zero the memory before releasing it: both tpm2_end_auth_session() and tpm_buf_check_hmac_response() do so. The tpm_dev_release() path is the only one that does not, leaving key material in freed slab memory until it is eventually overwritten.

Leer descripción completaMostrar menos

Use kfree_sensitive() for consistency with the rest of the driver and to ensure session keys are scrubbed during device teardown.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-46283",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "699e3efd6c645c741ea4d6d58282c56b6d108cf7",
              "lessThan": "dd3ac52ea7a001406c7dbc663aae4b9f89da679a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "699e3efd6c645c741ea4d6d58282c56b6d108cf7",
              "lessThan": "53e6d2d834df40960b655b353e7a8ff4d927e1c7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "699e3efd6c645c741ea4d6d58282c56b6d108cf7",
              "lessThan": "84ced03172da544c9f8c0862faad48104f519352",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "699e3efd6c645c741ea4d6d58282c56b6d108cf7",
              "lessThan": "c424d2664f08c77f08b4580b5f0cbaabf7c229b2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/char/tpm/tpm-chip.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.10",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.86",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.27",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/char/tpm/tpm-chip.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-06-08T17:16:46.063",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/53e6d2d834df40960b655b353e7a8ff4d927e1c7",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84ced03172da544c9f8c0862faad48104f519352",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c424d2664f08c77f08b4580b5f0cbaabf7c229b2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd3ac52ea7a001406c7dbc663aae4b9f89da679a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Use kfree_sensitive() to free auth session in tpm_dev_release()\n\ntpm_dev_release() uses plain kfree() to free chip->auth, which contains\nsensitive cryptographic material including HMAC session keys, nonces,\nand passphrase data (struct tpm2_auth).\n\nEvery other code path that frees this structure uses kfree_sensitive()\nto zero the memory before releasing it: both tpm2_end_auth_session()\nand tpm_buf_check_hmac_response() do so. The tpm_dev_release() path\nis the only one that does not, leaving key material in freed slab\nmemory until it is eventually overwritten.\n\nUse kfree_sensitive() for consistency with the rest of the driver and\nto ensure session keys are scrubbed during device teardown."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\ntpm: Usar kfree_sensitive() para liberar la sesión de autenticación en tpm_dev_release()\n\ntpm_dev_release() usa kfree() sin más para liberar chip->auth, que contiene material criptográfico sensible, incluyendo claves de sesión HMAC, nonces y datos de frase de contraseña (estructura tpm2_auth).\n\nTodas las demás rutas de código que liberan esta estructura usan kfree_sensitive() para poner a cero la memoria antes de liberarla: tanto tpm2_end_auth_session() como tpm_buf_check_hmac_response() lo hacen. La ruta de tpm_dev_release() es la única que no lo hace, dejando material de clave en la memoria slab liberada hasta que finalmente sea sobrescrito.\n\nUsar kfree_sensitive() para consistencia con el resto del controlador y para asegurar que las claves de sesión sean borradas durante el desmontaje del dispositivo."
    }
  ],
  "lastModified": "2026-07-23T08:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE217E72-2117-418C-97F0-213685E36DC0",
              "versionEndExcluding": "6.12.86",
              "versionStartIncluding": "6.10"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A10AC84F-C058-47D5-85B4-E6E51A613B74",
              "versionEndExcluding": "6.18.27",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CDB78D6D-22C3-4154-B0D0-94AF1CE5C2E3",
              "versionEndExcluding": "7.0.4",
              "versionStartIncluding": "6.19"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}