cbcvebase.
CVE-2025-68792
published 2026-01-13

CVE-2025-68792: In the Linux kernel, the following vulnerability has been resolved: tpm2-sessions: Fix out of range indexing in name_size 'name_size' does not have any range…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.13%
2.8th percentile
In the Linux kernel, the following vulnerability has been resolved: tpm2-sessions: Fix out of range indexing in name_size 'name_size' does not have any range checks, and it just directly indexes with TPM_ALG_ID, which could lead into memory corruption at worst. Address the issue by only processing known values and returning -EINVAL for unrecognized values. Make also 'tpm_buf_append_name' and 'tpm_buf_fill_hmac_session' fallible so that errors are detected before causing any spurious TPM traffic. End also the authorization session on failure in both of the functions, as the session state would be then by definition corrupted.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.18.3-1 (forky)linux 6.18.3-1 (forky)
linuxlinux
linuxlinux>= 1085b8276bb4239daa7008f0dcd5c973e4bd690f < 47e676ce4d68f461dfcab906f6aeb254f7276deb47e676ce4d68f461dfcab906f6aeb254f7276deb
linuxlinux>= 1085b8276bb4239daa7008f0dcd5c973e4bd690f < 04a3aa6e8c5f878cc51a8a1c90b6d3c54079bc4304a3aa6e8c5f878cc51a8a1c90b6d3c54079bc43
linuxlinux>= 1085b8276bb4239daa7008f0dcd5c973e4bd690f < 6e9722e9a7bfe1bbad649937c811076acf86e1fd6e9722e9a7bfe1bbad649937c811076acf86e1fd
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 6.10.0 < 6.12.666.12.66
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3
ubuntulinux-aws
ubuntulinux-aws-6.17
ubuntulinux-azure
ubuntulinux-azure-6.17
ubuntulinux-gcp
ubuntulinux-gcp-6.17
ubuntulinux-hwe-6.17
ubuntulinux-oem-6.17
ubuntulinux-oracle
ubuntulinux-oracle-6.17
ubuntulinux-raspi
ubuntulinux-realtime-6.17

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu6.4MEDIUM
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.