Repository navigation
cmcp v0.4.1
Anyone running 0.4.0 should upgrade.
Security
This release fixes GHSA-943q-hvhp-mrx2 (high), reported and fixed by Noah Ingwers.
On 0.4.0, verify_gateway_measurement() could return verified=True for a correctly signed TPM2_NV_Certify pair that does not refer to cMCP's configured TPM_NT_EXTEND object or its complete 32-byte range. The verifier compared the two signed TPM Names only with each other and never against trusted verifier policy, and a collector-claimed digest could produce a positive result when no expected digest was configured. An actor able to use an otherwise accepted AK could therefore certify attacker-arranged values from an ordinary or unapproved NV object and receive an authorization-grade verdict. No signature forgery was required.
Appraisal now requires a complete GatewayNvAppraisalPolicy supplied by the verifier: the exact authorized written TPM Name, offset zero, 32-byte extent, and expected gateway digest. Both attestations and the envelope copy must match it, and digest-only legacy calls fail closed. The producer side validates the complete public area and TPM-returned Name before any read, extend, or certify.
Scope limit, stated rather than implied. The startup NV-certify pair is not carried by the ordinary TRACE schema and verify_trace_claim() does not call verify_gateway_measurement(). This was a genuine false positive in the standalone verifier, not an end-to-end bypass in the ordinary request path. That is why it is scored high rather than critical. We are keeping the reporter's own scoring.
Breaking change
Callers of the appraisal primitive that omitted the full policy now fail closed. This is intentional.
Credit
Our thanks to Noah Ingwers, who found this while auditing the parser migration in #601, reported it with a genuine swtpm reproduction corpus covering both a same-handle ordinary object and a partial-range case, and supplied the complete fix with live TPM validation. A researcher acknowledgements section has been added to SECURITY.md.
Everything else
0.4.1 also carries the work accumulated on main since 0.4.0. See CHANGELOG.md for the full list.