Skip to content
Red HatCVE-2026-85769

Red Hat libtpms: denial of service

Medium6.5CVE-2026-85769 · Published Sep 4, 2026 · updated Sep 8, 2026

A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Flatpak: race condition
Medium5.8Sep 4
Red Hat libsoup.: reachable assertion
Medium5.9Sep 4
Red Hat Enterprise Linux 10: integer overflow
Medium6.5Sep 4
Red Hat: heap buffer overflow
High7.5Sep 4
Red Hat libsoup: use after free
High7.6Sep 4
Red Hat Ansible Automation Platform 2: improper signature check
Medium5.9Sep 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.