GPU VulnDB

Database/Firmware, BMC & network fabric

TCG TPM 2.0 reference implementation (CryptHmacSign): Out-of-bounds read in the reference implementation's HMAC signing

CVE-2025-2884Firmware, BMC & network fabriccurated

Impact

Out-of-bounds read in the reference implementation's HMAC signing helper because the signature scheme is not validated against the key's algorithm. Reads past the buffer can disclose TPM-internal memory - the one place in the system that is supposed to be opaque. Because this is the reference code, the same bug propagates into every fTPM, software TPM and vendor TPM derived from it, which is most of them.

Who can reach it

Local user able to issue TPM commands. On a shared or bare-metal node, that is any tenant.

What to do

Update to TPM 2.0 reference implementation 1.83 or later - in practice that arrives as a platform firmware/BIOS update, a swtpm/libtpms package update for virtualised TPMs, or nothing at all if your TPM vendor has not rebased. Virtualised TPMs are the easy case (package update plus VM restart); silicon and fTPM are a per-node firmware flash. Check both paths separately; fleets usually have some of each.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.