#1107617 libtpms: CVE-2025-49133: Fix potential out-of-bound access & abort due to HMAC signing issue #1107617
- Package:
- src:libtpms
- Source:
- src:libtpms
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2025-08-27 19:33:04 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for libtpms. CVE-2025-49133[0]: | Fix potential out-of-bound access & abort due to HMAC signing issue If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2025-49133 https://www.cve.org/CVERecord?id=CVE-2025-49133 [1] https://github.com/stefanberger/libtpms/commit/9f9baccdba9cd3fc32f1355613abd094b21f7ba0 Regards, Salvatore
I am uploading a NMU to fix this. The debdiff is attached.
We believe that the bug you reported is fixed in the latest version of libtpms, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1107617@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Bastian Germann <bage@debian.org> (supplier of updated libtpms package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Thu, 12 Jun 2025 08:15:52 +0200 Source: libtpms Architecture: source Version: 0.9.2-3.2 Distribution: unstable Urgency: medium Maintainer: Seunghun Han <kkamagui@gmail.com> Changed-By: Bastian Germann <bage@debian.org> Closes: 1107617 Changes: libtpms (0.9.2-3.2) unstable; urgency=medium . * Non-maintainer upload * Fix potential out-of-bound access (Closes: #1107617, CVE-2025-49133) Checksums-Sha1: e896d6ae4875affd7c17cfa5371acac2df65c2b9 1786 libtpms_0.9.2-3.2.dsc b4226211f0addd58b78777ca06d05fb4357fe141 13104 libtpms_0.9.2-3.2.debian.tar.xz a655576c23385dae048ea4efb7f26223291ce8e3 5258 libtpms_0.9.2-3.2_source.buildinfo Checksums-Sha256: d4522e2d850117e8813c99bd992c606073bf764d3efe76ed7db30c150bd30051 1786 libtpms_0.9.2-3.2.dsc f1aed22f4cbc8027239a87330118d5e481e7471ce189e4473c2d923e5c757372 13104 libtpms_0.9.2-3.2.debian.tar.xz deba02ac55e4fa47280672130149e6f2bb8710b9a81efa99beca97df658963f1 5258 libtpms_0.9.2-3.2_source.buildinfo Files: c2f030616c5040fcedeec9fe8db8659d 1786 libs optional libtpms_0.9.2-3.2.dsc b9c2031973a171b4c698b075c5588ccb 13104 libs optional libtpms_0.9.2-3.2.debian.tar.xz 7e9eaa81a78f87b853df7579d260b5c7 5258 libs optional libtpms_0.9.2-3.2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmhKiwEQHGJhZ2VAZGVi aWFuLm9yZwAKCRAfXHqLRVZDFFqjC/oCSgSCOd1vdODEtZExEMZdLA4oVtZ/L6Qo AnbkjsWnexgrIYhEv1PAY8zBTZ7h4tgYhi7dpQ2xgTtWhT/ulqPj+7Jla5tH6l6F a2emveOhpinBV6uLe0z8sS6BNdZXVhkVjLojoVBuDWeHkcoKooSVhQLM/s5vpjvt uHPNgopuKaT8wIeT0h+z/PlFSA36ksT24VSWjPJw27XGsN5bK8ajgzEsmmZJCTyc 4WGKZ+haTIuO3FbT4l69lkPUMcFvfZsVuEhBLB1X7E87li8gXuDruf24XeIr0WkA z1QauNVzpWFi4U/09/7hbZxGMLJAl1jY81J0cI65F4tbV+AbkBBrU8xRvRwKa7az J34fZSTi9ruvi7WW83lx5GB0koof6PRDBVDUScqL9U9CHMn7uq1gWRFkh0qKSfA1 jWzN6zBX89ZGRSR/JnPPg4W/t0XORsjGNjg9XaKhINH+hrkwdmp3W+d7c6wPlkum i+J6FxxhJ7ctUEHlfMTWaCPyl/ho7tw= =mPgl -----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of libtpms, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1107617@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Moritz Mühlenhoff <jmm@debian.org> (supplier of updated libtpms package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Mon, 25 Aug 2025 22:42:00 +0200 Source: libtpms Architecture: source Version: 0.9.2-3.1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: Seunghun Han <kkamagui@gmail.com> Changed-By: Moritz Mühlenhoff <jmm@debian.org> Closes: 1107617 Changes: libtpms (0.9.2-3.1+deb12u1) bookworm; urgency=medium . * CVE-2025-49133 (Closes: #1107617) Checksums-Sha1: 2e4fec9cd4ad94332f25cdcd746d59473fcd1034 1989 libtpms_0.9.2-3.1+deb12u1.dsc b8ac2a6047a396aed59e2d0a0899e0dbc91895e4 13004 libtpms_0.9.2-3.1+deb12u1.debian.tar.xz ca5d5bce4843761696db53e831e2127f745e64ac 7030 libtpms_0.9.2-3.1+deb12u1_amd64.buildinfo Checksums-Sha256: 8f2c24a4f2f6f141e66d458562bb50af379b53a3f7b105832eba9049d0b197d5 1989 libtpms_0.9.2-3.1+deb12u1.dsc 62a50a3586e15c2bd969a779734f2b127c825d30cf236f812be32efbc0e70f83 13004 libtpms_0.9.2-3.1+deb12u1.debian.tar.xz 08c70fdcf7a71ca91104a95b59ee91a7f0a5b1a96e037358195f934f6c9a980c 7030 libtpms_0.9.2-3.1+deb12u1_amd64.buildinfo Files: 607e21ba1c7f3e88e8cd302b65cbf70f 1989 libs optional libtpms_0.9.2-3.1+deb12u1.dsc 8fdcd873ae66de3a61ba5c20aebc2117 13004 libs optional libtpms_0.9.2-3.1+deb12u1.debian.tar.xz 966667281a02a3726c7ae5b67460dbc3 7030 libs optional libtpms_0.9.2-3.1+deb12u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJDBAEBCgAtFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmiuxm4PHGptbUBkZWJp YW4ub3JnAAoJEBDCk7bDfE42By4P/Ain6VtqokWqXgUAM0El6gKuT5NFpnRLTpjA RtVg+VM3aATua4k9aTtJjf23r98A9Akg2nuVIj1P0H6BNYtzBBLygCGekVFMpp6o kCOsFTAk0T106qK+L/Kf3h9mcYPtO2AWwEKu4QOOu0pmMlPyqXRC2gi3iz+5Svi6 bJa2/49Zay8/ID3cQQpiQVSFq6+PMV3GFgDmAvVhdy0i0nfC0EP2xiXv9BsSclS6 7JcRCyNSkgSW0xENtUKUwYat1yei9dL1pSYxWUibCwm4vTOVOMyyL/qd4rFXpvH9 Uvf7GAU0FCmufKR8AUd3QEGUxqjaypzOcCDIH7Oll1qhQlkaRwrVq0rLKOFbHlWK kCZVMtWKcIw95AzVUvrnfl2CuJEUNfxEWbn/4HormxQ//ZGrnZKVPcghVIB4/zgl sueN7PSEvJMoRHc8Zdoa5lWn9QGN45ImqgL5X8M16SXvJfH0nvOiQIo3if6qQ1xm tTJDLwutpaCbjnCW4c7s7z8fCVQspGFwL7P55sPamt74iB8PSR92IaUnPvVxsFLm tHwy41kKBG905INsnVxSjdPukBaF9B8QwyauW5MwhQzoD/PsCr3uVfnZ2/3TWsir lkqiwVHBNpXJVEvTnrEvx+nIZ06VNqHI8MueP8G2PmJpzhGaMMO/s/hdYuEHPb3k tIftB88o =ptk3 -----END PGP SIGNATURE-----