A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 2, 2022 |
| Debian | — | Upgrade libtpms | Jul 30, 2024 | Mar 2, 2022 |
| Oracle_linux | — | Upgrade swtpm-toolsUpgrade libtpmsUpgrade swtpm-develUpgrade libtpms-develUpgrade swtpm-libsUpgrade swtpm | Mar 22, 2022 | Jun 21, 2021 |
| Suse | — | Upgrade libtpms0Upgrade libtpms-devel | Dec 14, 2022 | Mar 2, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub