Description
In the Linux kernel, the following vulnerability has been resolved:

tpm: st33zp24: Return zero on status read failure

st33zp24_status() ignores the result of the transport read and returns
data even when no byte was received. The I2C transport, for example,
skips i2c_master_recv() when the register-select write is short or fails,
leaving data uninitialized. The resulting stack value can be interpreted
as TPM_STS flags and let status checks complete spuriously.

The status callback cannot propagate a transport error. Return zero
unless recv() reports exactly one byte. With no status bits set, callers
retry or take their existing timeout or error path instead of acting on
an invalid status value.

This issue was found by a static analysis checker and confirmed by manual
source review.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Invalid TPM status handling may allow bypass of security checks and incorrect system behavior
Action: Apply patch
AI Analysis

Impact

The st33zp24 TPM driver contained a flaw where the st33zp24_status() routine ignored the return value of the low‑level transport read. When the read failed or returned no bytes, the routine still returned stack data that had not been initialized. Uninitialized data can be interpreted as TPM status flags, leading the driver to report that the TPM is operational even though it is not. This can cause calling code to make incorrect decisions, such as skipping authentication checks or proceeding with operations that assume TPM availability.

Affected Systems

The vulnerability affects Linux kernel implementations that include the st33zp24 TPM driver. All kernel releases prior to the patch commit that added explicit error handling for status reads are considered vulnerable. Distribution kernels that ship the TPM subsystem without this fix—before the update is applied—remain at risk. The affected product is broadly the Linux kernel as a whole, with the specific driver component being st33zp24.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of active exploitation. However, an adversary who can influence the I2C bus or directly interact with the TPM could trigger a status read failure, causing the driver to return garbage data that is misinterpreted as a valid status. This could allow bypass of TPM‑based authentication or cause denial of service in systems that rely on TPM status for critical decisions. The lack of an explicit CVSS score suggests that the impact is primarily limited to scenarios where TPM status checks drive safety or security controls.

Generated by OpenCVE AI on September 20, 2026 at 04:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that incorporates the patch for st33zp24_status; the patch is available through the commit references listed in the advisory.
  • If an immediate kernel upgrade is not feasible, limit access to the TPM device by configuring udev rules or capabilities so that only trusted users or processes can interact with the device, thereby reducing the attack surface.
  • Modify any application logic that relies on TPM status to explicitly verify that status flags are set correctly and treat any unexpected value as an error condition, avoiding blind trust in the TPM status bitmask.

Generated by OpenCVE AI on September 20, 2026 at 04:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tpm: st33zp24: Return zero on status read failure st33zp24_status() ignores the result of the transport read and returns data even when no byte was received. The I2C transport, for example, skips i2c_master_recv() when the register-select write is short or fails, leaving data uninitialized. The resulting stack value can be interpreted as TPM_STS flags and let status checks complete spuriously. The status callback cannot propagate a transport error. Return zero unless recv() reports exactly one byte. With no status bits set, callers retry or take their existing timeout or error path instead of acting on an invalid status value. This issue was found by a static analysis checker and confirmed by manual source review.
Title tpm: st33zp24: Return zero on status read failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:51.585Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90070

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:55.940

Modified: 2026-09-17T17:16:55.940

Link: CVE-2026-90070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable

  • CWE-665

    Improper Initialization