Software TPM 2.0 Emulation Vulnerability in libtpms by Red Hat
CVE-2026-85769

6.5MEDIUM

What is CVE-2026-85769?

A flaw in libtpms, the software library for TPM 2.0 emulation, allows for a denial of service attack. When restoring the TPM 2.0 state, a malformed state blob can lead to an unvalidated oversized skip-block length. This results in an internal size counter becoming negative and bypassing a critical bounds check through unsafe signed-to-unsigned conversion. Exploitation of this vulnerability can cause crashes in the process using libtpms, leading to service disruptions in the emulated TPM device and any virtual machines depending on it, though no data corruption or information leakage occurs.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Isuka Sanuj (CyberCrew Inc. (株式会社CyberCrew)) and Leyao (ICT CAS) for reporting this issue.
.