Database/Firmware, BMC & network fabric

libtpms (CryptHmacSign, vTPM): Out-of-bounds read when signKey and signScheme are mismatched, aborting the vTPM
Impact
Out-of-bounds read when signKey and signScheme are mismatched, aborting the vTPM. libtpms is the TPM behind QEMU/KVM guests, so on a GPU cloud that rents VMs this is a guest reaching out and killing its own virtual TPM - which takes down measured boot and any disk unlock or key sealing that depended on it, and on some stacks takes the guest with it. The libtpms instance of the same defect as the TCG reference implementation issue, which is worth noting because they patch through completely different channels.
Who can reach it
A guest able to issue TPM commands to its vTPM - i.e. any tenant in a VM you provisioned with a virtual TPM. No escape required, no host access.
What to do
libtpms package update on the hypervisor hosts plus a restart of affected guests' swtpm processes - so a rolling VM restart rather than a firmware flash, which is the cheap end of this database. Do not assume patching the host TPM stack covers your physical TPMs or your platform firmware TPM; those are separate code paths with separate fixes.
References
Related entries
- Juniper Junos OS / Junos OS Evolved (rpd BGP session handling): A genuine, valid BGP UPDATE message resets a live BGPCVE-2025-52953 · Juniper Junos OS / Junos OS Evolved (rpd BGP session handling)Unscored
- Juniper Junos OS / Junos OS Evolved (annotate configuration command): The `annotate` configuration command can be usedCVE-2025-52989 · Juniper Junos OS / Junos OS Evolved (annotate configuration command)Unscored
- Juniper Junos OS (QFX5000-Series, EX4600-Series): A physical-access path into affected QFX5000 and EX4600 switchesCVE-2025-59957 · Juniper Junos OS (QFX5000-Series, EX4600-Series)Unscored
- Juniper Junos OS Evolved (QFX5000 / PTX, multicast packet handling): Crafted multicast packets crash and restartCVE-2025-59969 · Juniper Junos OS Evolved (QFX5000 / PTX, multicast packet handling)Unscored
- ASPEED crypto/ACRY accelerator driver (drivers/crypto/aspeed): The ACRY driver's probe error path and its remove pathCVE-2025-68172 · ASPEED crypto/ACRY accelerator driver (drivers/crypto/aspeed)Unscored
- Linux kernel mlx5_core firmware tracer (diag/fw_tracer): The firmware tracer took format strings directly from deviceCVE-2025-68816 · Linux kernel mlx5_core firmware tracer (diag/fw_tracer)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.