USN-7617-1: libtpms vulnerability
USN-7617-1: libtpms vulnerability
Publication date: 3 July 2025
Overview: libtpms could be made to crash if it received specially crafted input.
Packages
libtpms - TPM emulation library
Details
It was discovered that libtpms did not properly manage memory
when performing crafted cryptographic operations. An attacker could
possibly use this issue to cause a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
- 25.04 plucky libtpms0 – 0.9.3-0ubuntu4.25.04.1
- 24.10 oracular libtpms0 – 0.9.3-0ubuntu4.24.10.1
- 24.04 noble libtpms0 – 0.9.3-0ubuntu4.24.04.1
- 22.04 jammy libtpms0 – 0.9.3-0ubuntu1.22.04.2