---
id: CVE-2021-46922
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KEYS: trusted: Fix TPM reservation for seal/unseal

  The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM for seal
  and unseal operations") was correct on the mai…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KEYS: trusted: Fix TPM reservation for seal/unseal

  The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM for seal
  and unseal operations") was correct on the mai…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.10.20, < 5.10.33'
  - 'linux_kernel >= 5.11.3, < 5.11.17'
patched:
  - linux_kernel 5.11.17
published: '2024-02-27'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-46922'
references:
  - url: 'https://git.kernel.org/stable/c/39c8d760d44cb3fa0d67e8cd505df81cf4d80999'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9d5171eab462a63e2fbebfccf6026e92be018f20'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bf84ef2dd2ccdcd8f2658476d34b51455f970ce4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/39c8d760d44cb3fa0d67e8cd505df81cf4d80999'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/9d5171eab462a63e2fbebfccf6026e92be018f20'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://git.kernel.org/stable/c/bf84ef2dd2ccdcd8f2658476d34b51455f970ce4'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00241
epssPercentile: 0.13621
ingestedAt: '2026-08-04T10:39:38.314Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

KEYS: trusted: Fix TPM reservation for seal/unseal

The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM for seal
and unseal operations") was correct on the mailing list:

https://lore.kernel.org/linux-integrity/20210128235621.127925-4-jarkko@kernel.org/

But somehow got rebased so that the tpm_try_get_ops() in
tpm2_seal_trusted() got lost.  This causes an imbalanced put of the
TPM ops and causes oopses on TIS based hardware.

This fix puts back the lost tpm_try_get_ops()

## Affected

- `linux_kernel >= 5.10.20, < 5.10.33`
- `linux_kernel >= 5.11.3, < 5.11.17`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.11.17`
