We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2884

Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation



Description

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 and advisory VRT0009 of TCG standard TPM2.0

Reserved 2025-03-27 | Published 2025-06-10 | Updated 2025-06-11 | Assigner certcc

Problem types

CWE-125 Out-of-bounds Read

Product status

Any version before 1.83
affected

References

trustedcomputinggroup.org/about/security/

trustedcomputinggroup.org/...ry-Spec-v1.83-Errata_v1_pub.pdf

trustedcomputinggroup.org/...oads/VRT0009-Advisory-FINAL.pdf

cve.org (CVE-2025-2884)

nvd.nist.gov (CVE-2025-2884)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2884

Support options

Helpdesk Chat, Email, Knowledgebase