Database/Firmware, BMC & network fabric

libtpms (OpenSSL 3.x symmetric cipher IV handling): libtpms 0.10.0/0.10.1 built against OpenSSL 3.x returned
Impact
libtpms 0.10.0/0.10.1 built against OpenSSL 3.x returned the initial IV instead of the last IV for certain symmetric ciphers, weakening every subsequent encrypt and decrypt step in the chain. Anything a tenant's vTPM encrypted - sealed keys, protected blobs - is protected less than the cryptography claims. Quiet failure mode: nothing errors, the data is just weaker than the threat model assumes, and you only find out when someone attacks it.
Who can reach it
No active attacker needed to introduce the weakness - it is present in every affected operation. Exploiting it requires an attacker who obtains the ciphertext, which for vTPM state means host-level access or a leaked VM state file.
What to do
libtpms package update on hypervisor hosts and restart the swtpm processes. Because the weakness is in data already produced, rotate anything a vulnerable vTPM sealed rather than assuming the update is retroactive. Package-level, no firmware flash - but the re-sealing step is the part that takes planning on a fleet with long-lived guests.
References
Related entries
- Arm Trusted Firmware-A BL1/BL2 boot stages on platforms that load firmware from a Firmware Image Package (FIP)CVE-2026-34878 · Arm Trusted Firmware-A BL1/BL2 boot stages on platforms that load firmware from a Firmware Image Package (FIP) containerUnscored
- Linux kernel IPMI: refcount leak on the supplied-recv error path permanently pins the IPMI userCVE-2026-72040 · Linux kernel IPMI driver (i_ipmi_request supplied-recv error path)Unscored
- Linux kernel i2c-mlxbf (BlueField DPU I2C controller): mlxbf_i2c_init_resource() frees a resource struct and then readsCVE-2026-72140 · Linux kernel i2c-mlxbf (BlueField DPU I2C controller)Unscored
- Linux kernel mlxsw: failed LAG index allocation leaks a LAG reference on Spectrum switchesCVE-2026-72308 · Linux kernel mlxsw (Spectrum switch driver, LAG join error path)Unscored
- Linux kernel bnxt_re: uninitialised shared page mapped to userspace leaks kernel memoryCVE-2026-74584 · Linux kernel bnxt_re RDMA driver (ucontext shared page)Unscored
- Linux kernel PMBus hwmon: type confusion in the alert path reads past the attribute allocationCVE-2026-74711 · Linux kernel hwmon pmbus core (pmbus_notify attribute type confusion)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.