CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-2884: Out-of-Bounds read vulnerability in TCG TPM2.0 reference implementation

Description

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 of TCG standard TPM2.0

Classification

CVE ID: CVE-2025-2884

Problem Types

CWE-125 Out-of-bounds Read

Affected Products

Vendor: Trusted Computing Group

Product: TPM2.0

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.01% (probability of being exploited)

EPSS Percentile: 1.19% (scored less or equal to compared to others)

EPSS Date: 2025-06-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-2884
https://trustedcomputinggroup.org/about/security/
https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-v1.83-Errata_v1_pub.pdf

Timeline