CVE-2025-71077

Source
https://cve.org/CVERecord?id=CVE-2025-71077
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71077.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-71077
Downstream
Related
Published
2026-01-13T15:31:29.435Z
Modified
2026-03-12T02:17:18.704786Z
Summary
tpm: Cap the number of PCR banks
Details

In the Linux kernel, the following vulnerability has been resolved:

tpm: Cap the number of PCR banks

tpm2getpcr_allocation() does not cap any upper limit for the number of banks. Cap the limit to eight banks so that out of bounds values coming from external I/O cause on only limited harm.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71077.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bcfff8384f6c4e6627676ef07ccad9cfacd67849
Fixed
8ceee7288152bc121a6bf92997261838c78bfe06
Fixed
275c686f1e3cc056ec66c764489ec1fe1e51b950
Fixed
ceb70d31da5671d298bad94ae6c20e4bbb800f96
Fixed
d88481653d74d622d1d0d2c9bad845fc2cc6fd23
Fixed
b69492161c056d36789aee42a87a33c18c8ed5e1
Fixed
858344bc9210bea9ab2bdc7e9e331ba84c164e50
Fixed
faf07e611dfa464b201223a7253e9dc5ee0f3c9e

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71077.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
5.10.248
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.198
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.160
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.120
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.64
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-71077.json"