Skip to content

cmcp v0.4.1

Choose a tag to compare

@github-actions github-actions released this 02 Sep 22:06
· 111 commits to main since this release

Anyone running 0.4.0 should upgrade.

Security

This release fixes GHSA-943q-hvhp-mrx2 (high), reported and fixed by Noah Ingwers.

On 0.4.0, verify_gateway_measurement() could return verified=True for a correctly signed TPM2_NV_Certify pair that does not refer to cMCP's configured TPM_NT_EXTEND object or its complete 32-byte range. The verifier compared the two signed TPM Names only with each other and never against trusted verifier policy, and a collector-claimed digest could produce a positive result when no expected digest was configured. An actor able to use an otherwise accepted AK could therefore certify attacker-arranged values from an ordinary or unapproved NV object and receive an authorization-grade verdict. No signature forgery was required.

Appraisal now requires a complete GatewayNvAppraisalPolicy supplied by the verifier: the exact authorized written TPM Name, offset zero, 32-byte extent, and expected gateway digest. Both attestations and the envelope copy must match it, and digest-only legacy calls fail closed. The producer side validates the complete public area and TPM-returned Name before any read, extend, or certify.

Scope limit, stated rather than implied. The startup NV-certify pair is not carried by the ordinary TRACE schema and verify_trace_claim() does not call verify_gateway_measurement(). This was a genuine false positive in the standalone verifier, not an end-to-end bypass in the ordinary request path. That is why it is scored high rather than critical. We are keeping the reporter's own scoring.

Breaking change

Callers of the appraisal primitive that omitted the full policy now fail closed. This is intentional.

Credit

Our thanks to Noah Ingwers, who found this while auditing the parser migration in #601, reported it with a genuine swtpm reproduction corpus covering both a same-handle ordinary object and a partial-range case, and supplied the complete fix with live TPM validation. A researcher acknowledgements section has been added to SECURITY.md.

Everything else

0.4.1 also carries the work accumulated on main since 0.4.0. See CHANGELOG.md for the full list.