# CVE-2024-29039

## Summary

- **CVE ID:** CVE-2024-29039
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-807
- **Published:** Jun 28, 2024
- **Last Modified:** Mar 13, 2026

## Description

tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in the PCR input file.  As a result, digest values are incorrectly mapped to PCR slots and banks, providing a misleading picture of the TPM state. This issue has been patched in version 5.7.

## Affected Products

- tpm2-software — tpm2-tools (< 5.7)

## References

- [CNA](https://github.com/tpm2-software/tpm2-tools/security/advisories/GHSA-8rjm-5f5f-h4q6)
- [CNA](https://github.com/tpm2-software/tpm2-tools/releases/tag/5.7)
- [CVE](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GI4JFEZBKQQUPJ4RWK6IHEWXAFCEJDPI/)
- [CVE](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EFR7SVEWCOXORHPCLLGXEMHFMIGG2MFE/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.98%
- **EPSS Percentile:** 60.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._