CVE-2025-49133 is an out-of-bounds read vulnerability in Libtpms, a library integrating TPM functionality into hypervisors like Qemu, specifically affecting the CryptHmacSign function. This flaw can be triggered by user-mode applications sending malicious commands to a TPM 2.0/vTPM based on the affected TCG reference implementation. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, and its primary impact is a denial of service, making the vTPM unavailable to a virtual machine. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Patches are available in Libtpms versions 0.7.12, 0.8.10, 0.9.7, and 0.10.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.7.11CPE matchmatch criteria | cpe:2.3:a:libtpms_project:libtpms:0.7.11:*:*:*:*:*:*:* | ||
0.8.9CPE matchmatch criteria | cpe:2.3:a:libtpms_project:libtpms:0.8.9:*:*:*:*:*:*:* | ||
0.9.6CPE matchmatch criteria | cpe:2.3:a:libtpms_project:libtpms:0.9.6:*:*:*:*:*:*:* | ||
0.10.0CPE matchmatch criteria | cpe:2.3:a:libtpms_project:libtpms:0.10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.