Upstream information
CVE-2025-49133 at MITRE
Description
Libtpms is a library that targets the integration of TPM functionality into hypervisors, primarily into Qemu. Libtpms, which is derived from the TPM 2.0 reference implementation code published by the Trusted Computing Group, is prone to a potential out of bounds (OOB) read vulnerability. The vulnerability occurs in the 'CryptHmacSign' function with an inconsistent pairing of the signKey and signScheme parameters, where the signKey is ALG_KEYEDHASH key and inScheme is an ECC or RSA scheme. The reported vulnerability is in the 'CryptHmacSign' function, which is defined in the "Part 4: Supporting Routines - Code" document, section "7.151 - /tpm/src/crypt/CryptUtil.c ". This vulnerability can be triggered from user-mode applications by sending malicious commands to a TPM 2.0/vTPM (swtpm) whose firmware is based on an affected TCG reference implementation. The effect on libtpms is that it will cause an abort due to the detection of the out-of-bounds access, thus for example making a vTPM (swtpm) unavailable to a VM. This vulnerability is fixed in 0.7.12, 0.8.10, 0.9.7, and 0.10.1.
Overall state of this security issue: Pending
This issue is currently rated as having moderate severity.
CVSS v3 Scores
| CVSS detail | CNA (GitHub) | National Vulnerability Database | SUSE |
| Base Score | 5.9 | 5.5 | 5.9 |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H |
| Attack Vector | Local | Local | Local |
| Attack Complexity | Low | Low | Low |
| Privileges Required | Low | Low | Low |
| User Interaction | Required | None | Required |
| Scope | Changed | Unchanged | Changed |
| Confidentiality Impact | None | None | None |
| Integrity Impact | None | None | None |
| Availability Impact | High | High | High |
| CVSSv3 Version | 3.1 | 3.1 | 3.1 |
SUSE Bugzilla entry:
1244528 [NEW]
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| Container suse/sl-micro/6.0/baremetal-os-container:latest | | |
| Container suse/sl-micro/6.0/base-os-container:latest | iproute2 >= 06.4-1.1
libzypp >= 017.38.14-slfo.1.1_1.1
| |
| Container suse/sl-micro/6.0/toolbox:latest | libzypp >= 017.38.14-slfo.1.1_1.1
| |
| Container suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.13 | kpartx >= 00.10.8+212+suse.3dc4ecc-slfo.1.1_1.1
libmpath0 >= 00.10.8+212+suse.3dc4ecc-slfo.1.1_1.1
multipath-tools >= 00.10.8+212+suse.3dc4ecc-slfo.1.1_1.1
| |
Image SL-Micro
Image SL-Micro-Default
Image SL-Micro-Default-SelfInstall
Image SL-Micro-Default-encrypted
Image SL-Micro-Default-qcow | libtpms0 >= 00.9.6-slfo.1.1_2.1
| |
Image SLE-Micro
Image SLE-Micro-Azure
Image SLE-Micro-BYOS
Image SLE-Micro-BYOS-Azure
Image SLE-Micro-BYOS-EC2
Image SLE-Micro-BYOS-GCE
Image SLE-Micro-EC2
Image SLE-Micro-GCE | iproute2 >= 06.4-1.1
libzypp >= 017.38.14-slfo.1.1_1.1
runc >= 01.3.1-1.1
| |
| SUSE Liberty Linux 8 | hivex >= 01.3.18-23.module+el8.9.0+18724+20190c23
hivex-devel >= 01.3.18-23.module+el8.9.0+18724+20190c23
libguestfs >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-appliance >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-bash-completion >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-devel >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-gfs2 >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-gobject >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-gobject-devel >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-inspect-icons >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-java >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-java-devel >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-javadoc >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-man-pages-ja >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-man-pages-uk >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-rescue >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-rsync >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-tools >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-tools-c >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libguestfs-winsupport >= 08.10-1.module+el8.10.0+19908+9938c7c9
libguestfs-xfs >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
libiscsi >= 01.18.0-8.module+el8.9.0+18724+20190c23
libiscsi-devel >= 01.18.0-8.module+el8.9.0+18724+20190c23
libiscsi-utils >= 01.18.0-8.module+el8.9.0+18724+20190c23
libnbd >= 01.6.0-6.module+el8.10.0+22250+3c790083
libnbd-bash-completion >= 01.6.0-6.module+el8.10.0+22250+3c790083
libnbd-devel >= 01.6.0-6.module+el8.10.0+22250+3c790083
libtpms >= 00.9.1-3.20211126git1ff6fe1f43.module+el8.10.0+23348+204cfc70
libtpms-devel >= 00.9.1-3.20211126git1ff6fe1f43.module+el8.10.0+23348+204cfc70
libvirt >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-client >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-config-network >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-config-nwfilter >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-interface >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-network >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-nodedev >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-nwfilter >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-qemu >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-secret >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-core >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-disk >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-gluster >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-iscsi >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-iscsi-direct >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-logical >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-mpath >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-rbd >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-driver-storage-scsi >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-daemon-kvm >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-dbus >= 01.3.0-2.module+el8.9.0+18724+20190c23
libvirt-devel >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-docs >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-libs >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-lock-sanlock >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-nss >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
libvirt-wireshark >= 08.0.0-23.4.module+el8.10.0+23205+d8da55c1
lua-guestfs >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
nbdfuse >= 01.6.0-6.module+el8.10.0+22250+3c790083
nbdkit >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-bash-completion >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-basic-filters >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-basic-plugins >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-curl-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-devel >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-example-plugins >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-gzip-filter >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-gzip-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-linuxdisk-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-nbd-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-python-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-server >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-ssh-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-tar-filter >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-tar-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-tmpdisk-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-vddk-plugin >= 01.24.0-5.module+el8.9.0+18724+20190c23
nbdkit-xz-filter >= 01.24.0-5.module+el8.9.0+18724+20190c23
netcf >= 00.2.8-12.module+el8.9.0+18724+20190c23
netcf-devel >= 00.2.8-12.module+el8.9.0+18724+20190c23
netcf-libs >= 00.2.8-12.module+el8.9.0+18724+20190c23
perl-Sys-Guestfs >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
perl-Sys-Virt >= 08.0.0-1.module+el8.9.0+18724+20190c23
perl-hivex >= 01.3.18-23.module+el8.9.0+18724+20190c23
python3-hivex >= 01.3.18-23.module+el8.9.0+18724+20190c23
python3-libguestfs >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
python3-libnbd >= 01.6.0-6.module+el8.10.0+22250+3c790083
python3-libvirt >= 08.0.0-2.module+el8.9.0+18724+20190c23
qemu-guest-agent >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-img >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-block-curl >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-block-gluster >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-block-iscsi >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-block-rbd >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-block-ssh >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-common >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-core >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-docs >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-hw-usbredir >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-ui-opengl >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
qemu-kvm-ui-spice >= 15:6.2.0-53.module+el8.10.0+23081+c18b1ee3.4
ruby-hivex >= 01.3.18-23.module+el8.9.0+18724+20190c23
ruby-libguestfs >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
seabios >= 01.16.0-4.module+el8.9.0+19570+14a90618
seabios-bin >= 01.16.0-4.module+el8.9.0+19570+14a90618
seavgabios-bin >= 01.16.0-4.module+el8.9.0+19570+14a90618
sgabios >= 1:0.20170427git-3.module+el8.9.0+18724+20190c23
sgabios-bin >= 1:0.20170427git-3.module+el8.9.0+18724+20190c23
supermin >= 05.2.1-2.module+el8.9.0+18724+20190c23
supermin-devel >= 05.2.1-2.module+el8.9.0+18724+20190c23
swtpm >= 00.7.0-4.20211109gitb79fd91.module+el8.9.0+18724+20190c23
swtpm-devel >= 00.7.0-4.20211109gitb79fd91.module+el8.9.0+18724+20190c23
swtpm-libs >= 00.7.0-4.20211109gitb79fd91.module+el8.9.0+18724+20190c23
swtpm-tools >= 00.7.0-4.20211109gitb79fd91.module+el8.9.0+18724+20190c23
swtpm-tools-pkcs11 >= 00.7.0-4.20211109gitb79fd91.module+el8.9.0+18724+20190c23
virt-dib >= 1:1.44.0-9.module+el8.9.0+18724+20190c23
virt-v2v >= 1:1.42.0-22.module+el8.9.0+18724+20190c23
virt-v2v-bash-completion >= 1:1.42.0-22.module+el8.9.0+18724+20190c23
virt-v2v-man-pages-ja >= 1:1.42.0-22.module+el8.9.0+18724+20190c23
virt-v2v-man-pages-uk >= 1:1.42.0-22.module+el8.9.0+18724+20190c23
| Patchnames: ESSA-2025:3052 (x86_64) |
| SUSE Liberty Linux 9 | libtpms >= 0.9.1-5.20211126git1ff6fe1f43.el9_6
| Patchnames: RHSA-2025:12100 (i686,x86_64) |
SUSE Linux Enterprise Module for Server Applications 15 SP7
SUSE Linux Enterprise Server 15 SP7
SUSE Linux Enterprise Server for SAP Applications 15 SP7 | libtpms-devel >= 00.9.6-150600.3.3.1
libtpms0 >= 00.9.6-150600.3.3.1
| Patchnames: SUSE-SLE-Module-Server-Applications-15-SP7-2026-1388 (aarch64,ppc64le,s390x,x86_64) |
SUSE Linux Enterprise Server 16.0
SUSE Linux Enterprise Server for SAP applications 16.0 | libtpms0 >= 00.10.0-160000.5.1
| Patchnames: SUSE-SLES-16.0-714 (aarch64,ppc64le,s390x,x86_64) |
| SUSE Linux Enterprise Server 16.1 | libtpms0 >= 0.10.0-160099.5.1
| Patchnames: SUSE Linux Enterprise Server 16.1 GA libtpms0-0.10.0-160099.5.1 (aarch64,ppc64le,s390x,x86_64) |
| SUSE Linux Micro 6.0 | | Patchnames: SUSE-SLE-Micro-6.0-656 (aarch64,s390x,x86_64) |
| SUSE Linux Micro 6.1 | libtpms0 >= 00.9.6-slfo.1.1_2.1
| Patchnames: SUSE-SLE-Micro-6.1-476 (aarch64,ppc64le,s390x,x86_64) |
| SUSE Linux Micro 6.2 | libtpms0 >= 00.10.0-160000.5.1
| Patchnames: SUSE-SL-Micro-6.2-714 (aarch64,ppc64le,s390x,x86_64) |
| openSUSE Leap 15.6 | libtpms-devel >= 00.9.6-150600.3.3.1
libtpms0 >= 00.9.6-150600.3.3.1
| Patchnames: openSUSE-SLE-15.6-2026-1388 |
| openSUSE Leap 16.0 | libtpms-devel >= 00.10.0-160000.5.1
libtpms0 >= 00.10.0-160000.5.1
| Patchnames: openSUSE-Leap-16.0-714 |
| openSUSE Tumbleweed | libtpms-devel >= 0.10.1-1.1
libtpms0 >= 0.10.1-1.1
| Patchnames: openSUSE-Tumbleweed-2025-15244 |
Status of this issue by product and package
Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification. The updates are grouped by state of their lifecycle. SUSE product lifecycles are documented on the lifecycle page.
| Product(s) | Source package | State |
| Products under general support and receiving all security fixes. |
| SUSE Linux Enterprise Micro 5.3 | libtpms | Affected |
| SUSE Linux Enterprise Micro 5.4 | libtpms | Affected |
| SUSE Linux Enterprise Micro 5.5 | libtpms | Affected |
| SUSE Linux Enterprise Module for Server Applications 15 SP7 | libtpms | Released |
| SUSE Linux Enterprise Server 15 SP7 | libtpms | Released |
| SUSE Linux Enterprise Server 16.0 | libtpms | Released |
| SUSE Linux Enterprise Server 16.1 | libtpms | Released |
| SUSE Linux Enterprise Server for SAP Applications 15 SP7 | libtpms | Released |
| SUSE Linux Enterprise Server for SAP applications 16.0 | libtpms | Released |
| SUSE Linux Enterprise Server for SAP applications 16.1 | libtpms | Released |
| SUSE Linux Micro 6.0 | libtpms | Released |
| SUSE Linux Micro 6.1 | libtpms | Released |
| SUSE Linux Micro 6.2 | libtpms | Released |
| openSUSE Leap 16.0 | libtpms | Released |
| Products under Long Term Service Pack support and receiving important and critical security fixes. |
| SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS | libtpms | Affected |
| SUSE Linux Enterprise High Performance Computing 15 SP5 | libtpms | Affected |
| SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS | libtpms | Affected |
| SUSE Linux Enterprise Module for Server Applications 15 SP4 | libtpms | Affected |
| SUSE Linux Enterprise Module for Server Applications 15 SP5 | libtpms | Affected |
| SUSE Linux Enterprise Module for Server Applications 15 SP6 | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP4 | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP4-LTSS | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP5 | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP5-LTSS | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP6 | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP6-LTSS | libtpms | Affected |
| SUSE Linux Enterprise Server for SAP Applications 15 SP4 | libtpms | Affected |
| SUSE Linux Enterprise Server for SAP Applications 15 SP5 | libtpms | Affected |
| SUSE Linux Enterprise Server for SAP Applications 15 SP6 | libtpms | Affected |
| Products past their end of life and not receiving proactive updates anymore. |
| SUSE Enterprise Storage 7.1 | libtpms | Affected |
| SUSE Linux Enterprise High Performance Computing 15 SP3 | libtpms | Affected |
| SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS | libtpms | Affected |
| SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS | libtpms | Affected |
| SUSE Linux Enterprise High Performance Computing 15 SP4 | libtpms | Affected |
| SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS | libtpms | Affected |
| SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS | libtpms | Affected |
| SUSE Linux Enterprise Micro 5.1 | libtpms | Affected |
| SUSE Linux Enterprise Micro 5.2 | libtpms | Affected |
| SUSE Linux Enterprise Module for Server Applications 15 SP3 | libtpms | Affected |
| SUSE Linux Enterprise Real Time 15 SP3 | libtpms | Affected |
| SUSE Linux Enterprise Real Time 15 SP4 | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP3 | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP3-BCL | libtpms | Affected |
| SUSE Linux Enterprise Server 15 SP3-LTSS | libtpms | Affected |
| SUSE Linux Enterprise Server for SAP Applications 15 SP3 | libtpms | Affected |
| SUSE Manager Proxy 4.2 | libtpms | Affected |
| SUSE Manager Proxy 4.3 | libtpms | Affected |
| SUSE Manager Proxy LTS 4.3 | libtpms | Affected |
| SUSE Manager Retail Branch Server 4.2 | libtpms | Affected |
| SUSE Manager Retail Branch Server 4.3 | libtpms | Affected |
| SUSE Manager Retail Branch Server LTS 4.3 | libtpms | Affected |
| SUSE Manager Server 4.2 | libtpms | Affected |
| SUSE Manager Server 4.3 | libtpms | Affected |
| SUSE Manager Server LTS 4.3 | libtpms | Affected |
| openSUSE Leap 15.3 | libtpms | Affected |
| openSUSE Leap 15.4 | libtpms | Affected |
| openSUSE Leap 15.5 | libtpms | Affected |
| openSUSE Leap 15.6 | libtpms | Released |
| openSUSE Leap Micro 5.2 | libtpms | Affected |
| openSUSE Leap Micro 5.3 | libtpms | Affected |
| openSUSE Leap Micro 5.4 | libtpms | Affected |
| openSUSE Leap Micro 5.5 | libtpms | Affected |
SUSE Timeline for this CVE
CVE page created: Wed Jun 11 00:00:31 2025
CVE page last modified: Fri Sep 11 19:26:49 2026