rpm package
opensuse/swtpm&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/swtpm&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-75900 | Med | 6.1 | < 0.10.2-1.1 | 0.10.2-1.1 | Aug 19, 2026 | An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, ca | |
| CVE-2020-28407 | Hig | 7.1 | < 0.6.1-1.1 | 0.6.1-1.1 | Nov 3, 2023 | In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall. | |
| CVE-2022-23645 | Med | 6.2 | < 0.7.1-1.1 | 0.7.1-1.1 | Feb 18, 2022 | swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid valu |
- affected < 0.10.2-1.1fixed 0.10.2-1.1
An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, ca
- affected < 0.6.1-1.1fixed 0.6.1-1.1
In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
- affected < 0.7.1-1.1fixed 0.7.1-1.1
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid valu