Login
Newsletter
Werbung

Sicherheit: Denial of Service in libtpms
Aktuelle Meldungen Distributionen
Name: Denial of Service in libtpms
ID: USN-7617-1
Distribution: Ubuntu
Plattformen: Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 24.10, Ubuntu 25.04
Datum: Fr, 4. Juli 2025, 00:03
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49133
Applikationen: libtpms

Originalnachricht

--===============2180061919846912998==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

==========================================================================
Ubuntu Security Notice USN-7617-1
July 03, 2025

libtpms vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.04
- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

libtpms could be made to crash if it received specially crafted
input.

Software Description:
- libtpms: TPM emulation library

Details:

It was discovered that libtpms did not properly manage memory
when performing crafted cryptographic operations. An attacker could
possibly use this issue to cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.04
libtpms0 0.9.3-0ubuntu4.25.04.1

Ubuntu 24.10
libtpms0 0.9.3-0ubuntu4.24.10.1

Ubuntu 24.04 LTS
libtpms0 0.9.3-0ubuntu4.24.04.1

Ubuntu 22.04 LTS
libtpms0 0.9.3-0ubuntu1.22.04.2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7617-1
CVE-2025-49133

Package Information:
https://launchpad.net/ubuntu/+source/libtpms/0.9.3-0ubuntu4.25.04.1
https://launchpad.net/ubuntu/+source/libtpms/0.9.3-0ubuntu4.24.10.1
https://launchpad.net/ubuntu/+source/libtpms/0.9.3-0ubuntu4.24.04.1
https://launchpad.net/ubuntu/+source/libtpms/0.9.3-0ubuntu1.22.04.2

--===============2180061919846912998==
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmhm5BYACgkQcpJm3tlz
hgHNgxAAk8Pm0zzMW6Iov38jCch2FtuJGiBNL0DLObJwCp3G33a3qF21NuIExb6o
wm10XbdrRMpgaPZxgTJO0TQeK3ifD4YHng3M/+7SaB9r1ZbGF3C/5o9J4mRcAZbD
X6ulc9NcjIQE0GSsq/EhIjoMmjNo3R6fq4bWsOjRHmsXlMspikrRC2wBNhoNEYIn
zS6BIvzqPmXK2y4bLK69OONw7HzrWr569YaSrkFQKNWvsUraUnvGqz8mXpTd2ME4
EG5aiXElBaGs1YpcPJYgkLjhZVZSXXb9oVhElkODblioFxieSavkWPfPapCFGXMg
4ANX9mvBqQHn7AipHhrvS4H2b/I1oY2zK9Nlig0oHzqj9+2rpwA8aZ8Lx2OOlfB8
Fbe0HSzlt+j1A+r9Ois9ogpcrcjutrbx3pV9gVEgiioJDyKCCGaCUGyS3BCvrEIq
Jhs4BY17zGgEDRI0UDYdPCCxqsv8AV1dulOKOLR3gZWakSG+cSeJpUqU6XR2Z6mw
zd9DwWENPgrV/CGjSUgY86SijxLYhAL8yS7BECBRJgYyI/0FWCSBg99eawE8Row7
r+Q1XRX4iN/DFKCm/IT8u5NUfSYIRG+yb6tJvEpJtY8kWCNd5K9jiOQuS2AWz2rf
gWFK30j+THKsGhz823X9byqZ3Gjd730fYP8iBEgVKi42GljNmbg=
=8wBC
-----END PGP SIGNATURE-----

--===============2180061919846912998==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung