CVE-2025-49133
published 2025-06-10CVE-2025-49133: Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.3th percentile
Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libtpms | < libtpms 0.9.2-3.1+deb12u1 (bookworm) | libtpms 0.9.2-3.1+deb12u1 (bookworm) |
| libtpms_project | libtpms | — | — |
| libtpms_project | libtpms | — | — |
| libtpms_project | libtpms | — | — |
| libtpms_project | libtpms | — | — |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.1+deb12u1 | 0.9.2-3.1+deb12u1 |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.2 | 0.9.2-3.2 |
| libtpms_project | libtpms | >= 0 < 0.9.2-3.2 | 0.9.2-3.2 |
| msrc | azl3_libtpms_0.9.6-8_on_azure_linux_3.0 | — | — |
| msrc | cbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0 | — | — |
| stefanberger | libtpms | — | — |
| stefanberger | libtpms | — | — |
| stefanberger | libtpms | — | — |
| stefanberger | libtpms | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libtpms vulnerability
vendor_ubuntu·2025-07-03
CVE-2025-49133 libtpms vulnerability
Title: libtpms vulnerability
Summary: libtpms could be made to crash if it received specially crafted
input.
It was discovered that libtpms did not properly manage memory
when performing crafted cryptographic operations. An attacker could
possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Libtpms contains a possible out-of-bound access and abort due to HMAC signing issue
vendor_msrc·2025-06-10·CVSS 5.9
CVE-2025-49133 [MEDIUM] CWE-125 Libtpms contains a possible out-of-bound access and abort due to HMAC signing issue
Libtpms contains a possible out-of-bound access and abort due to HMAC signing issue
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner
Red Hat
libtpms: Libtpms Out-of-Bounds Read Vulnerability
vendor_redhat·2025-06-10·CVSS 5.9
CVE-2025-49133 [MEDIUM] CWE-125 libtpms: Libtpms Out-of-Bounds Read Vulnerability
libtpms: Libtpms Out-of-Bounds Read Vulnerability
Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending
Microsoft
drm/amdkfd: svm range restore work deadlock when process exit
vendor_msrc·2025-02-11·CVSS 5.5
CVE-2022-49133 [MEDIUM] drm/amdkfd: svm range restore work deadlock when process exit
drm/amdkfd: svm range restore work deadlock when process exit
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Debian
CVE-2025-49133: libtpms - Libtpms is a library that targets the integration of TPM functionality into hype...
vendor_debian·2025·CVSS 5.9
CVE-2025-49133 [MEDIUM] CVE-2025-49133: libtpms - Libtpms is a library that targets the integration of TPM functionality into hype...
Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose
OSV
CVE-2025-49133: Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu
osv·2025-06-10·CVSS 5.5
CVE-2025-49133 [MEDIUM] CVE-2025-49133: Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu
Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/stefanberger/libtpms/commit/04b2d8e9afc0a9b6bffe562a23e58c0de11532d1https://github.com/stefanberger/libtpms/security/advisories/GHSA-25w5-6fjj-hf8ghttps://trustedcomputinggroup.org/resource/tpm-library-specificationhttps://trustedcomputinggroup.org/wp-content/uploads/TPM-2.0-1.83-Part-4-Supporting-Routines-Code.pdfhttps://www.kb.cert.org/vuls/id/282450
2025-06-10
Published