<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:30:25 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:12100 — Moderate: libtpms security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:12100</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libtpms&lt;/p&gt;
&lt;p&gt;The libtpms is a library providing Trusted Platform Module (TPM) functionality for virtual machines.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libtpms: Libtpms Out-of-Bounds Read Vulnerability (CVE-2025-49133)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libtpms&lt;/p&gt;
&lt;p&gt;The libtpms is a library providing Trusted Platform Module (TPM) functionality for virtual machines.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libtpms: Libtpms Out-of-Bounds Read Vulnerability (CVE-2025-49133)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:12100</guid>
    </item>
    <item>
      <title>bdu:2025-11088</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-11088</link>
      <description>bdu:2025-11088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-11088</guid>
    </item>
    <item>
      <title>ESSA-2025:3052 — Moderate: virt:rhel and virt-devel:rhel security update</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2025:3052</link>
      <description>&lt;p&gt;Moderate: virt:rhel and virt-devel:rhel security update&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Moderate: virt:rhel and virt-devel:rhel security update&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2025:3052</guid>
    </item>
    <item>
      <title>EUVD-2026-257969</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257969</link>
      <description>EUVD-2026-257969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257969</guid>
    </item>
    <item>
      <title>fkie_cve-2025-49133</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-49133</link>
      <description>&lt;p&gt;Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the &amp;#34;Part 4: Supporting Routines – Code&amp;#34; document, section &amp;#34;7.151 - /tpm/src/crypt/CryptUtil.c &amp;#34;. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the &amp;#34;Part 4: Supporting Routines – Code&amp;#34; document, section &amp;#34;7.151 - /tpm/src/crypt/CryptUtil.c &amp;#34;. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-49133</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-49133 — Libtpms contains a possible out-of-bound access and abort due to HMAC signing issue</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-49133</link>
      <description>msrc_CVE-2025-49133</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-49133</guid>
    </item>
    <item>
      <title>OESA-2025-1836 — libtpms security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1836</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libtpms&lt;/p&gt;
&lt;p&gt;A library providing TPM functionality for VMs. Targeted for integration into Qemu.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the &amp;amp;quot;Part 4: Supporting Routines – Code&amp;amp;quot; document, section &amp;amp;quot;7.151 - /tpm/src/crypt/CryptUtil.c &amp;amp;quot;. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.(CVE-2025-49133)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: libtpms&lt;/p&gt;
&lt;p&gt;A library providing TPM functionality for VMs. Targeted for integration into Qemu.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the &amp;amp;quot;Part 4: Supporting Routines – Code&amp;amp;quot; document, section &amp;amp;quot;7.151 - /tpm/src/crypt/CryptUtil.c &amp;amp;quot;. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.(CVE-2025-49133)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1836</guid>
    </item>
    <item>
      <title>RHSA-2025:12111 — Red Hat Security Advisory: libtpms security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:12111</link>
      <description>&lt;p&gt;libtpms: Libtpms Out-of-Bounds Read Vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libtpms: Libtpms Out-of-Bounds Read Vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:12111</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21035-1 — Security update for libtpms</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21035-1</link>
      <description>&lt;p&gt;Security update for libtpms&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libtpms&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21035-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-49133</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49133</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: libtpms, Ubuntu:24.04:LTS: libtpms&lt;/p&gt;
&lt;p&gt;Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the &amp;#34;Part 4: Supporting Routines – Code&amp;#34; document, section &amp;#34;7.151 - /tpm/src/crypt/CryptUtil.c &amp;#34;. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: libtpms, Ubuntu:24.04:LTS: libtpms&lt;/p&gt;
&lt;p&gt;Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the ‘CryptHmacSign’ function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the ‘CryptHmacSign’ function, which is defined in the &amp;#34;Part 4: Supporting Routines – Code&amp;#34; document, section &amp;#34;7.151 - /tpm/src/crypt/CryptUtil.c &amp;#34;. This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-49133</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1669 — Red Hat Enterprise Linux (libtpms): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1669</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1669</guid>
    </item>
  </channel>
</rss>
