cbcvebase.
CVE-2025-71077
published 2026-01-13

CVE-2025-71077: In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allocation() does not cap any upper limit for…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allocation() does not cap any upper limit for the number of banks. Cap the limit to eight banks so that out of bounds values coming from external I/O cause on only limited harm.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= bcfff8384f6c4e6627676ef07ccad9cfacd67849 < 8ceee7288152bc121a6bf92997261838c78bfe068ceee7288152bc121a6bf92997261838c78bfe06
linuxlinux>= bcfff8384f6c4e6627676ef07ccad9cfacd67849 < 275c686f1e3cc056ec66c764489ec1fe1e51b950275c686f1e3cc056ec66c764489ec1fe1e51b950
linuxlinux>= bcfff8384f6c4e6627676ef07ccad9cfacd67849 < ceb70d31da5671d298bad94ae6c20e4bbb800f96ceb70d31da5671d298bad94ae6c20e4bbb800f96
linuxlinux>= bcfff8384f6c4e6627676ef07ccad9cfacd67849 < d88481653d74d622d1d0d2c9bad845fc2cc6fd23d88481653d74d622d1d0d2c9bad845fc2cc6fd23
linuxlinux>= bcfff8384f6c4e6627676ef07ccad9cfacd67849 < b69492161c056d36789aee42a87a33c18c8ed5e1b69492161c056d36789aee42a87a33c18c8ed5e1
linuxlinux>= bcfff8384f6c4e6627676ef07ccad9cfacd67849 < 858344bc9210bea9ab2bdc7e9e331ba84c164e50858344bc9210bea9ab2bdc7e9e331ba84c164e50
linuxlinux>= bcfff8384f6c4e6627676ef07ccad9cfacd67849 < faf07e611dfa464b201223a7253e9dc5ee0f3c9efaf07e611dfa464b201223a7253e9dc5ee0f3c9e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.3-16.18.3-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 5.1.0 < 5.10.2485.10.248
linuxlinux_kernel>= 5.1.1 < 5.10.2485.10.248
linuxlinux_kernel>= 5.11 < 5.15.1985.15.198
linuxlinux_kernel>= 5.11.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1606.1.160
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13 < 6.18.36.18.3
linuxlinux_kernel>= 6.13.0 < 6.18.36.18.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.