CVE-2025-71077

In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allocation() does not cap any upper limit for the number of banks. Cap the limit to eight banks so that out of bounds values coming from external I/O cause on only limited harm.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.1:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: tpm: Limitar el número de bancos PCR tpm2_get_pcr_allocation() no establece ningún límite superior para el número de bancos. Establecer el límite en ocho bancos para que los valores fuera de límites provenientes de E/S externa causen solo un daño limitado.

25 Mar 2026, 19:00

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/275c686f1e3cc056ec66c764489ec1fe1e51b950 - () https://git.kernel.org/stable/c/275c686f1e3cc056ec66c764489ec1fe1e51b950 - Patch
References () https://git.kernel.org/stable/c/858344bc9210bea9ab2bdc7e9e331ba84c164e50 - () https://git.kernel.org/stable/c/858344bc9210bea9ab2bdc7e9e331ba84c164e50 - Patch
References () https://git.kernel.org/stable/c/8ceee7288152bc121a6bf92997261838c78bfe06 - () https://git.kernel.org/stable/c/8ceee7288152bc121a6bf92997261838c78bfe06 - Patch
References () https://git.kernel.org/stable/c/b69492161c056d36789aee42a87a33c18c8ed5e1 - () https://git.kernel.org/stable/c/b69492161c056d36789aee42a87a33c18c8ed5e1 - Patch
References () https://git.kernel.org/stable/c/ceb70d31da5671d298bad94ae6c20e4bbb800f96 - () https://git.kernel.org/stable/c/ceb70d31da5671d298bad94ae6c20e4bbb800f96 - Patch
References () https://git.kernel.org/stable/c/d88481653d74d622d1d0d2c9bad845fc2cc6fd23 - () https://git.kernel.org/stable/c/d88481653d74d622d1d0d2c9bad845fc2cc6fd23 - Patch
References () https://git.kernel.org/stable/c/faf07e611dfa464b201223a7253e9dc5ee0f3c9e - () https://git.kernel.org/stable/c/faf07e611dfa464b201223a7253e9dc5ee0f3c9e - Patch
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Linux
Linux linux Kernel
CPE cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.1:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*

19 Jan 2026, 13:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/275c686f1e3cc056ec66c764489ec1fe1e51b950 -
  • () https://git.kernel.org/stable/c/8ceee7288152bc121a6bf92997261838c78bfe06 -

13 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 16:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-71077

Mitre link : CVE-2025-71077

CVE.ORG link : CVE-2025-71077


JSON object : View

Products Affected

linux

  • linux_kernel