Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-49133

18
FAUCET Score

CVE-2025-49133 is an out-of-bounds read vulnerability in Libtpms, a library integrating TPM functionality into hypervisors like Qemu, specifically affecting the CryptHmacSign function. This flaw can be triggered by user-mode applications sending malicious commands to a TPM 2.0/vTPM based on the affected TCG reference implementation. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, and its primary impact is a denial of service, making the vTPM unavailable to a virtual machine. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Patches are available in Libtpms versions 0.7.12, 0.8.10, 0.9.7, and 0.10.1.

Impacted Technologies

VendorProductVersion(s)CPE
0.7.11CPE matchmatch criteria
cpe:2.3:a:libtpms_project:libtpms:0.7.11:*:*:*:*:*:*:*
0.8.9CPE matchmatch criteria
cpe:2.3:a:libtpms_project:libtpms:0.8.9:*:*:*:*:*:*:*
0.9.6CPE matchmatch criteria
cpe:2.3:a:libtpms_project:libtpms:0.9.6:*:*:*:*:*:*:*
0.10.0CPE matchmatch criteria
cpe:2.3:a:libtpms_project:libtpms:0.10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.5
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 22nd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 libtpms 0.9.6-8 on Azure Linux 3.0Fixed in: 0.9.6-8
microsoftpatch availablevia msrc
Product: 19614-17084Fixed in: 0.9.6-8
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: virt-devel:rhel-8100020250722092921.489197e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: virt:rhel-8060020250716064909.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: virt:rhel-8060020250716064909.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: virt:rhel-8060020250716064909.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: virt:rhel-8080020250715121528.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: virt:rhel-8080020250715121528.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libtpms-0:0.9.1-5.20211126git1ff6fe1f43.el9_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: libtpms-0:0.9.1-5.20211126git1ff6fe1f43.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: libtpms-0:0.9.1-5.20211126git1ff6fe1f43.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: libtpms-0:0.9.6-11.el10_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: virt:rhel-8100020250722092921.489197e6
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8 Advanced VirtualizationFixed in: virt:8.2/libtpms
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8 Advanced VirtualizationFixed in: virt:av/libtpms

Vendor Advisories (2)

redhatCVE-2025-49133Moderate

libtpms: Libtpms Out-of-Bounds Read Vulnerability

Jun 10, 2025
microsoft2025-Jun/CVE-2025-49133Moderate

Libtpms contains a possible out-of-bound access and abort due to HMAC signing issue

Jun 10, 2025

References

kb.cert.org / vuls/id/282450
github.com / stefanberger/libtpms/commit/04b2d8e9afc0a9b6bffe562a23e58c0de11532d1
Patch
github.com / stefanberger/libtpms/security/advisories/GHSA-25w5-6fjj-hf8g
Third Party Advisory
trustedcomputinggroup.org / resource/tpm-library-specification
Product
trustedcomputinggroup.org / wp-content/uploads/TPM-2.0-1.83-Part-4-Supporting-Routines-Code.pdf
Product