[coreboot-gerrit] Change in coreboot[master]: security/tpm: Fix TPM software stack vulnerability

Philipp Deppenwiese (Code Review) gerrit at coreboot.org
Thu Mar 15 12:42:12 CET 2018


Philipp Deppenwiese has posted comments on this change. ( https://review.coreboot.org/25184 )

Change subject: security/tpm: Fix TPM software stack vulnerability
......................................................................


Patch Set 2:

(1 comment)

https://review.coreboot.org/#/c/25184/1/src/security/tpm/tss/tcg-1.2/tss.c
File src/security/tpm/tss/tcg-1.2/tss.c:

https://review.coreboot.org/#/c/25184/1/src/security/tpm/tss/tcg-1.2/tss.c@241
PS1, Line 241: 		if (result_length > length)
> I am not a fun of asserts - what if this is just a glitch, do we want to crash the device? […]
Ack



-- 
To view, visit https://review.coreboot.org/25184
To unsubscribe, or for help writing mail filters, visit https://review.coreboot.org/settings

Gerrit-Project: coreboot
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: I1618b2cc579d189bccca7a781e2bed0976a8b471
Gerrit-Change-Number: 25184
Gerrit-PatchSet: 2
Gerrit-Owner: Philipp Deppenwiese <zaolin.daisuki at gmail.com>
Gerrit-Reviewer: Aaron Durbin <adurbin at chromium.org>
Gerrit-Reviewer: Paul Menzel <paulepanter at users.sourceforge.net>
Gerrit-Reviewer: Philipp Deppenwiese <zaolin.daisuki at gmail.com>
Gerrit-Reviewer: Vadim Bendebury <vbendeb at google.com>
Gerrit-Reviewer: build bot (Jenkins) <no-reply at coreboot.org>
Gerrit-CC: Vadim Bendebury <vbendeb at chromium.org>
Gerrit-Comment-Date: Thu, 15 Mar 2018 11:42:12 +0000
Gerrit-HasComments: Yes
Gerrit-HasLabels: No
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.coreboot.org/pipermail/coreboot-gerrit/attachments/20180315/80729262/attachment.html>


More information about the coreboot-gerrit mailing list