Source: libtpms Version: 0.10.2-5 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for libtpms. CVE-2026-85769[0]: | A flaw was found in libtpms, a library that provides software TPM | 2.0 emulation. When restoring TPM 2.0 state (for example during a | virtual machine's power-on or state/migration restore), a malformed | state blob can supply an oversized skip-block length that is not | validated against the remaining size of the input buffer. This can | drive an internal size counter negative, which bypasses a subsequent | bounds check due to an unsafe signed-to-unsigned conversion, causing | the parser to read memory outside the bounds of the heap buffer | holding the state data. Successful exploitation can crash the | process hosting libtpms (such as swtpm), resulting in a denial of | service of the emulated TPM device and the virtual machine that | depends on it. No data corruption or information disclosure was | confirmed. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-85769 https://www.cve.org/CVERecord?id=CVE-2026-85769 [1] https://bugzilla.redhat.com/show_bug.cgi?id=2528538 [2] https://github.com/stefanberger/libtpms/issues/614 [3] https://github.com/stefanberger/libtpms/commit/b1462888180d896af03cae0487e8d45009cc445e Please adjust the affected versions in the BTS as needed. Regards, Salvatore

