tpm: fix a race condition in tpm2_unseal_trusted()