Software TPM 2.0 Emulation Vulnerability in libtpms by Red Hat
CVE-2026-85769
6.5MEDIUM
What is CVE-2026-85769?
A flaw in libtpms, the software library for TPM 2.0 emulation, allows for a denial of service attack. When restoring the TPM 2.0 state, a malformed state blob can lead to an unvalidated oversized skip-block length. This results in an internal size counter becoming negative and bypassing a critical bounds check through unsafe signed-to-unsigned conversion. Exploitation of this vulnerability can cause crashes in the process using libtpms, leading to service disruptions in the emulated TPM device and any virtual machines depending on it, though no data corruption or information leakage occurs.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Isuka Sanuj (CyberCrew Inc. (株式会社CyberCrew)) and Leyao (ICT CAS) for reporting this issue.