CVE Database
/

CVE-2025-71077

Back to search

CVE-2025-71077

Published: Jan 13, 2026

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allocation() does not cap any upper limit for the number of banks. Cap the limit to eight banks so that out of bounds values coming from external I/O cause on only limited harm.

VendorProductVersions

Linux

Linux

affected
bcfff8384f6c4e6627676ef07ccad9cfacd67849 - < 8ceee7288152bc121a6bf92997261838c78bfe06
affected
bcfff8384f6c4e6627676ef07ccad9cfacd67849 - < 275c686f1e3cc056ec66c764489ec1fe1e51b950
affected
bcfff8384f6c4e6627676ef07ccad9cfacd67849 - < ceb70d31da5671d298bad94ae6c20e4bbb800f96
affected
bcfff8384f6c4e6627676ef07ccad9cfacd67849 - < d88481653d74d622d1d0d2c9bad845fc2cc6fd23
affected
bcfff8384f6c4e6627676ef07ccad9cfacd67849 - < b69492161c056d36789aee42a87a33c18c8ed5e1

+2 more versions

Linux

Linux

affected
5.1
unaffected
0 - < 5.1
unaffected
5.10.248 - <= 5.10.*
unaffected
5.15.198 - <= 5.15.*
unaffected
6.1.160 - <= 6.1.*

+4 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now