{"id":"CVE-2021-46922","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix TPM reservation for seal/unseal\n\nThe original patch 8c657a0590de (\"KEYS: trusted: Reserve TPM for seal\nand unseal operations\") was correct on the mai…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix TPM reservation for seal/unseal\n\nThe original patch 8c657a0590de (\"KEYS: trusted: Reserve TPM for seal\nand unseal operations\") was correct on the mai…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 5.10.20, < 5.10.33","linux_kernel >= 5.11.3, < 5.11.17"],"patched":["linux_kernel 5.11.17"],"published":"2024-02-27","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-46922","references":[{"url":"https://git.kernel.org/stable/c/39c8d760d44cb3fa0d67e8cd505df81cf4d80999","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9d5171eab462a63e2fbebfccf6026e92be018f20","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bf84ef2dd2ccdcd8f2658476d34b51455f970ce4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/39c8d760d44cb3fa0d67e8cd505df81cf4d80999","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/9d5171eab462a63e2fbebfccf6026e92be018f20","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.kernel.org/stable/c/bf84ef2dd2ccdcd8f2658476d34b51455f970ce4","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00241,"epssPercentile":0.15564,"ingestedAt":"2026-08-04T10:39:38.314Z","slug":"CVE-2021-46922","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix TPM reservation for seal/unseal\n\nThe original patch 8c657a0590de (\"KEYS: trusted: Reserve TPM for seal\nand unseal operations\") was correct on the mailing list:\n\nhttps://lore.kernel.org/linux-integrity/20210128235621.127925-4-jarkko@kernel.org/\n\nBut somehow got rebased so that the tpm_try_get_ops() in\ntpm2_seal_trusted() got lost.  This causes an imbalanced put of the\nTPM ops and causes oopses on TIS based hardware.\n\nThis fix puts back the lost tpm_try_get_ops()\n\n## Affected\n\n- `linux_kernel >= 5.10.20, < 5.10.33`\n- `linux_kernel >= 5.11.3, < 5.11.17`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 5.11.17`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}