<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:31:29.002245+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:12100</id>
    <title>ALSA-2025:12100 — Moderate: libtpms security update</title>
    <updated>2026-10-04T00:31:29.038856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: libtpms</p>
<p>The libtpms is a library providing Trusted Platform Module (TPM) functionality for virtual machines.</p>
<p>Security Fix(es):</p>
<p>* libtpms: Libtpms Out-of-Bounds Read Vulnerability (CVE-2025-49133)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:12100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11088</id>
    <title>bdu:2025-11088</title>
    <updated>2026-10-04T00:31:29.038920+00:00</updated>
    <content>bdu:2025-11088</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2025:3052</id>
    <title>ESSA-2025:3052 — Moderate: virt:rhel and virt-devel:rhel security update</title>
    <updated>2026-10-04T00:31:29.038937+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Moderate: virt:rhel and virt-devel:rhel security update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2025:3052"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257969</id>
    <title>EUVD-2026-257969</title>
    <updated>2026-10-04T00:31:29.038963+00:00</updated>
    <content>EUVD-2026-257969</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49133</id>
    <title>fkie_cve-2025-49133</title>
    <updated>2026-10-04T00:31:29.038976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-49133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-49133</id>
    <title>msrc_CVE-2025-49133 — Libtpms contains a possible out-of-bound access and abort due to HMAC signing issue</title>
    <updated>2026-10-04T00:31:29.039007+00:00</updated>
    <content>msrc_CVE-2025-49133</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-49133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1836</id>
    <title>OESA-2025-1836 — libtpms security update</title>
    <updated>2026-10-04T00:31:29.039023+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: libtpms</p>
<p>A library providing TPM functionality for VMs. Targeted for integration into Qemu.

Security Fix(es):</p>
<p>Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the &amp;quot;Part 4: Supporting Routines – Code&amp;quot; document, section &amp;quot;7.151 - /tpm/src/crypt/CryptUtil.c &amp;quot;. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.(CVE-2025-49133)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1836"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:12111</id>
    <title>RHSA-2025:12111 — Red Hat Security Advisory: libtpms security update</title>
    <updated>2026-10-04T00:31:29.039055+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libtpms: Libtpms Out-of-Bounds Read Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:12111"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21035-1</id>
    <title>SUSE-SU-2026:21035-1 — Security update for libtpms</title>
    <updated>2026-10-04T00:31:29.039072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libtpms</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21035-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49133</id>
    <title>UBUNTU-CVE-2025-49133</title>
    <updated>2026-10-04T00:31:29.039085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: libtpms, Ubuntu:24.04:LTS: libtpms</p>
<p>Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the "Part 4: Supporting Routines – Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1669</id>
    <title>WID-SEC-W-2025-1669 — Red Hat Enterprise Linux (libtpms): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-04T00:31:29.039112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1669"/>
  </entry>
</feed>
