Vulnerability Description
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tianocore | Edk2 | 201808 |
References
- https://bugzilla.tianocore.org/show_bug.cgi?id=3499Issue TrackingPermissions RequiredThird Party Advisory
- https://bugzilla.tianocore.org/show_bug.cgi?id=3499Issue TrackingPermissions RequiredThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/06/msg00007.html
FAQ
What is CVE-2021-38576?
CVE-2021-38576 is a vulnerability with a CVSS score of 7.5 (HIGH). A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the sy...
How severe is CVE-2021-38576?
CVE-2021-38576 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-38576?
Check the references section above for vendor advisories and patch information. Affected products include: Tianocore Edk2.