TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 of TCG standard TPM2.0
CVE ID: CVE-2025-2884
Vendor: Trusted Computing Group
Product: TPM2.0
EPSS Score: 0.01% (probability of being exploited)
EPSS Percentile: 1.19% (scored less or equal to compared to others)
EPSS Date: 2025-06-18 (when was this score calculated)