Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves two vulnerabilities can now be installed.. # Security update for libtpms Announcement ID: SUSE-SU-2026:21581-1 Release Date: 2026-05-06T18:19:25Z Rating: moderate References: * bsc#1244528 * bsc#1260439 Cross-References: * CVE-2025-49133 * CVE-2026-21444 CVSS scores: * CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21444 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-21444 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for libtpms fixes the following issues: * CVE-2025-49133: Fixed potential out of bounds (OOB) read vulnerability (bsc#1244528). * CVE-2026-21444: Fixed remote data confidentiality compromise via incorrect Initialization Vector (IV) handling (bsc#1260439). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-714=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libtpms-debugsource-0.10.0-160000.5.1 * libtpms0-debuginfo-0.10.0-160000.5.1 * libtpms0-0.10.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49133.html * https://www.suse.com/security/cve/CVE-2026-21444.html * https://bugzilla.suse.com/show_bug.cgi?id=1244528 * https://bugzilla.suse.com/show_bug.cgi?id=1260439 . SUSE provides a security update for libtpms addressing moderate vulnerabilities enhancingsystem integrity and safety.. SUSE libtpms update security issues moderate vulnerabilities. . LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for libtpms Announcement ID: SUSE-SU-2026:21571-1 Release Date: 2026-05-06T18:16:54Z Rating: moderate References: * bsc#1244528 * bsc#1260439 Cross-References: * CVE-2025-49133 * CVE-2026-21444 CVSS scores: * CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21444 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-21444 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libtpms fixes the following issues: * CVE-2025-49133: Fixed potential out of bounds (OOB) read vulnerability (bsc#1244528). * CVE-2026-21444: Fixed remote data confidentiality compromise via incorrect Initialization Vector (IV) handling (bsc#1260439). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-714=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-714=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libtpms0-0.10.0-160000.5.1 * libtpms-debugsource-0.10.0-160000.5.1 * libtpms0-debuginfo-0.10.0-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libtpms0-0.10.0-160000.5.1 *libtpms-debugsource-0.10.0-160000.5.1 * libtpms0-debuginfo-0.10.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49133.html * https://www.suse.com/security/cve/CVE-2026-21444.html * https://bugzilla.suse.com/show_bug.cgi?id=1244528 * https://bugzilla.suse.com/show_bug.cgi?id=1260439 . An SUSE update fixing libtpms vulnerabilities includes instructions for safe installation. Stay secure with the patch!. libtpms update,SUSE security,moderate vulnerabilities,SUSE Linux patch. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libtpms Announcement ID: SUSE-SU-2026:1388-1 Release Date: 2026-04-16T09:18:28Z Rating: moderate References: * bsc#1244528 Cross-References: * CVE-2025-49133 CVSS scores: * CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libtpms fixes the following issues: * CVE-2025-49133: Fixed potential out of bounds (OOB) read vulnerability (bsc#1244528) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-1388=1 SUSE-2026-1388=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-1388=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libtpms-debugsource-0.9.6-150600.3.3.1 * libtpms-devel-0.9.6-150600.3.3.1 * libtpms0-debuginfo-0.9.6-150600.3.3.1 * libtpms0-0.9.6-150600.3.3.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtpms-debugsource-0.9.6-150600.3.3.1 * libtpms-devel-0.9.6-150600.3.3.1 * libtpms0-debuginfo-0.9.6-150600.3.3.1 * libtpms0-0.9.6-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49133.html * https://bugzilla.suse.com/show_bug.cgi?id=1244528 . SUSE has released a security advisory forlibtpms addressing a moderate-level out of bounds read issue. Install updates promptly.. SUSE Security Update, libtpms Vulnerability, openSUSE Patch, Moderate Security Issue. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libtpms Announcement ID: SUSE-SU-2026:21035-1 Release Date: 2026-04-08T14:28:15Z Rating: moderate References: * bsc#1244528 Cross-References: * CVE-2025-49133 CVSS scores: * CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libtpms fixes the following issues: * CVE-2025-49133: out-of-bounds (OOB) access due to HMAC signing issue leads to abort and vTPM DoS (bsc#1244528). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-476=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libtpms0-debuginfo-0.9.6-slfo.1.1_2.1 * libtpms-debugsource-0.9.6-slfo.1.1_2.1 * libtpms0-0.9.6-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49133.html * https://bugzilla.suse.com/show_bug.cgi?id=1244528 . Critical patch for libtpms in SUSE Linux addresses out-of-bounds access vulnerability and prevents DoS attacks. Install recommended update.. libtpms patch security SUSE. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libtpms Announcement ID: SUSE-SU-2026:21064-1 Release Date: 2026-04-08T14:16:30Z Rating: moderate References: * bsc#1244528 Cross-References: * CVE-2025-49133 CVSS scores: * CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libtpms fixes the following issues: * CVE-2025-49133: out-of-bounds (OOB) access due to HMAC signing issue leads to abort and vTPM DoS (bsc#1244528). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-656=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libtpms-debugsource-0.9.6-2.1 * libtpms0-debuginfo-0.9.6-2.1 * libtpms0-0.9.6-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49133.html * https://bugzilla.suse.com/show_bug.cgi?id=1244528 . Critical update for libtpms addressing a moderate severity OOB access issue in SUSE Linux Micro 6.0. Update ASAP.. libtpms security patch, Denial of Service SUSE, SUSE Linux Micro update, libtpms OOB access, security advisory SUSE. . LinuxSecurity.com Team
Upgrade to libtpms 0.10.2 fixing CVE-2026-21444. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-14ecf2c0cd 2026-01-18 01:43:54.889957+00:00 -------------------------------------------------------------------------------- Name : libtpms Product : Fedora 42 Version : 0.10.2 Release : 1.fc42 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. -------------------------------------------------------------------------------- Update Information: Upgrade to libtpms 0.10.2 fixing CVE-2026-21444 -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 2 2026 Stefan Berger - 0.10.2-1 - Upgrade to libtpms 0.10.2 fixing CVE-2026-21444 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2426838 - CVE-2026-21444 libtpms: return of wrong initialization vector when certain symmetric ciphers are used https://bugzilla.redhat.com/show_bug.cgi?id=2426838 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-14ecf2c0cd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Upgrade to libtpms 0.10.2 fixing CVE-2026-21444. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-21a2a74849 2026-01-18 01:41:01.671057+00:00 -------------------------------------------------------------------------------- Name : libtpms Product : Fedora 43 Version : 0.10.2 Release : 1.fc43 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. -------------------------------------------------------------------------------- Update Information: Upgrade to libtpms 0.10.2 fixing CVE-2026-21444 -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 2 2026 Stefan Berger - 0.10.2-1 - Upgrade to libtpms 0.10.2 fixing CVE-2026-21444 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2426838 - CVE-2026-21444 libtpms: return of wrong initialization vector when certain symmetric ciphers are used https://bugzilla.redhat.com/show_bug.cgi?id=2426838 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-21a2a74849' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
MGASA-2025-0248 - Updated libtpms package fixes security vulnerability. MGASA-2025-0248 - Updated libtpms package fixes security vulnerability Publication date: 27 Oct 2025 URL: https://advisories.mageia.org/MGASA-2025-0248.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-49133 Description: It was discovered that libtpms had a potential out-of-bound access & abort due to HMAC signing issue (CVE-2025-49133). References: - https://bugs.mageia.org/show_bug.cgi?id=34396 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.