Логотип exploitDog
bind:CVE-2025-49133
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-49133

Количество 12

Количество 12

ubuntu логотип

CVE-2025-49133

8 месяцев назад

Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example mak...

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2025-49133

8 месяцев назад

Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example mak...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2025-49133

8 месяцев назад

Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2025-49133

6 месяцев назад

Libtpms contains a possible out-of-bound access and abort due to HMAC signing issue

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2025-49133

8 месяцев назад

Libtpms is a library that targets the integration of TPM functionality ...

CVSS3: 5.9
EPSS: Низкий
rocky логотип

RLSA-2025:16428

4 месяца назад

Moderate: libtpms security update

EPSS: Низкий
rocky логотип

RLSA-2025:12527

5 месяцев назад

Moderate: virt:rhel and virt-devel:rhel security update

EPSS: Низкий
rocky логотип

RLSA-2025:12100

4 месяца назад

Moderate: libtpms security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-16428

5 месяцев назад

ELSA-2025-16428: libtpms security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-12527

6 месяцев назад

ELSA-2025-12527: virt:rhel and virt-devel:rhel security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-12100

7 месяцев назад

ELSA-2025-12100: libtpms security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-11088

8 месяцев назад

Уязвимость функции CryptHmacSign() библиотеки libtpms связана с чтением за границами буфера в памяти. Эксплуатация уязвимости может позволить нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-49133

Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example mak...

CVSS3: 5.9
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2025-49133

Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example mak...

CVSS3: 5.9
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-49133

Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making

CVSS3: 5.9
0%
Низкий
8 месяцев назад
msrc логотип
CVE-2025-49133

Libtpms contains a possible out-of-bound access and abort due to HMAC signing issue

CVSS3: 5.9
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-49133

Libtpms is a library that targets the integration of TPM functionality ...

CVSS3: 5.9
0%
Низкий
8 месяцев назад
rocky логотип
RLSA-2025:16428

Moderate: libtpms security update

0%
Низкий
4 месяца назад
rocky логотип
RLSA-2025:12527

Moderate: virt:rhel and virt-devel:rhel security update

0%
Низкий
5 месяцев назад
rocky логотип
RLSA-2025:12100

Moderate: libtpms security update

0%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2025-16428

ELSA-2025-16428: libtpms security update (MODERATE)

5 месяцев назад
oracle-oval логотип
ELSA-2025-12527

ELSA-2025-12527: virt:rhel and virt-devel:rhel security update (MODERATE)

6 месяцев назад
oracle-oval логотип
ELSA-2025-12100

ELSA-2025-12100: libtpms security update (MODERATE)

7 месяцев назад
fstec логотип
BDU:2025-11088

Уязвимость функции CryptHmacSign() библиотеки libtpms связана с чтением за границами буфера в памяти. Эксплуатация уязвимости может позволить нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
0%
Низкий
8 месяцев назад

Уязвимостей на страницу