VDB
BDU%3A2025-11088
BDU%3A2025-11088
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Уязвимость функции CryptHmacSign() библиотеки libtpms связана с чтением за границами буфера в памяти. Эксплуатация уязвимости может позволить нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
4.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trusted Computing Group, АО «ИВК», Сообщество свободного программного обеспечения, АО «СберТех», ООО «НЦПР» | Trusted Platform Module, АЛЬТ СП 10, libtpms, Platform V SberLinux OS Server (запись в едином реестре российских программ №18785), МСВСфера |
Timeline
- Sep 14, 2025 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://github.com/stefanberger/libtpms/commit/04b2d8e9afc0a9b6bffe562a23e58c0de11532d1 url
- https://trustedcomputinggroup.org/resource/tpm-library-specification url
- https://trustedcomputinggroup.org/wp-content/uploads/TPM-2.0-1.83-Part-4-Supporting-Routines-Code.pdf url
- https://github.com/stefanberger/libtpms/security/advisories/GHSA-25w5-6fjj-hf8g advisory
- https://altsp.su/obnovleniya-bezopasnosti/ advisory
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2025:12100?lang=ru advisory