Impact
The st33zp24 TPM driver contained a flaw where the st33zp24_status() routine ignored the return value of the low‑level transport read. When the read failed or returned no bytes, the routine still returned stack data that had not been initialized. Uninitialized data can be interpreted as TPM status flags, leading the driver to report that the TPM is operational even though it is not. This can cause calling code to make incorrect decisions, such as skipping authentication checks or proceeding with operations that assume TPM availability.
Affected Systems
The vulnerability affects Linux kernel implementations that include the st33zp24 TPM driver. All kernel releases prior to the patch commit that added explicit error handling for status reads are considered vulnerable. Distribution kernels that ship the TPM subsystem without this fix—before the update is applied—remain at risk. The affected product is broadly the Linux kernel as a whole, with the specific driver component being st33zp24.
Risk and Exploitability
The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of active exploitation. However, an adversary who can influence the I2C bus or directly interact with the TPM could trigger a status read failure, causing the driver to return garbage data that is misinterpreted as a valid status. This could allow bypass of TPM‑based authentication or cause denial of service in systems that rely on TPM status for critical decisions. The lack of an explicit CVSS score suggests that the impact is primarily limited to scenarios where TPM status checks drive safety or security controls.
OpenCVE Enrichment
Debian DLA
Debian DSA