Are there plans to update this repo with the CVE fixes described in https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-184-Errata-1-PUBLISH.pdf? Would help downstreams do that they don't have to translate the PDF into proper patches and carry those around out of tree (see e.g. https://lore.kernel.org/cip-dev/cover.1786712498.git.jan.kiszka@siemens.com/).
Furthermore, it would be good to issue also security advisories here. Could be short ones, just linking the original PDFs. My concern is that vulnerability tracking tools will have a hard time matching the CVEs to this code base as the advisories contain no repo references, and this repo so far no vulnerability notices.
All in all, I appreciate the detailed information made available about the issues. However, the structure and format in which that was provided was... rather "unusual".
Are there plans to update this repo with the CVE fixes described in https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-184-Errata-1-PUBLISH.pdf? Would help downstreams do that they don't have to translate the PDF into proper patches and carry those around out of tree (see e.g. https://lore.kernel.org/cip-dev/cover.1786712498.git.jan.kiszka@siemens.com/).
Furthermore, it would be good to issue also security advisories here. Could be short ones, just linking the original PDFs. My concern is that vulnerability tracking tools will have a hard time matching the CVEs to this code base as the advisories contain no repo references, and this repo so far no vulnerability notices.
All in all, I appreciate the detailed information made available about the issues. However, the structure and format in which that was provided was... rather "unusual".