Debian Package Tracker
Register | Log in
Subscribe

libtpms

Choose email to subscribe with

general
  • source: libtpms (main)
  • version: 0.10.2-5
  • maintainer: Luca Boccassi (DMD)
  • uploaders: Seunghun Han [DMD]
  • arch: any
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 0.9.2-3.1+deb12u1
  • old-sec: 0.9.2-3.1~deb12u1
  • stable: 0.9.2-3.2
  • testing: 0.10.2-5
  • unstable: 0.10.2-5
versioned links
  • 0.9.2-3.1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.9.2-3.1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.9.2-3.2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.10.2-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libtpms-dev
  • libtpms0
action needed
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-85769: A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.
Created: 2026-09-05 Last update: 2026-09-06 18:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-85769: A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.
Created: 2026-09-05 Last update: 2026-09-06 18:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-85769: A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.
Created: 2026-09-05 Last update: 2026-09-06 18:30
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-85769: (needs triaging) A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-05 Last update: 2026-09-06 18:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-03-31 15:01
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-03-08] libtpms 0.10.2-5 MIGRATED to testing (Debian testing watch)
  • [2026-03-05] Accepted libtpms 0.10.2-5 (source) into unstable (Luca Boccassi)
  • [2026-03-05] Accepted libtpms 0.10.2-4 (source) into unstable (Luca Boccassi)
  • [2026-03-04] Accepted libtpms 0.10.2-3 (source) into unstable (Luca Boccassi)
  • [2026-02-10] libtpms 0.10.2-2 MIGRATED to testing (Debian testing watch)
  • [2026-02-07] Accepted libtpms 0.10.2-2 (source) into unstable (Luca Boccassi)
  • [2026-01-06] libtpms 0.10.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-03] Accepted libtpms 0.10.2-1 (source) into unstable (Luca Boccassi)
  • [2025-10-04] libtpms 0.10.1-2 MIGRATED to testing (Debian testing watch)
  • [2025-10-01] Accepted libtpms 0.10.1-2 (source) into unstable (Luca Boccassi)
  • [2025-09-30] Accepted libtpms 0.10.1-1 (source) into unstable (Luca Boccassi)
  • [2025-08-27] Accepted libtpms 0.9.2-3.1+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Moritz Mühlenhoff)
  • [2025-06-14] libtpms 0.9.2-3.2 MIGRATED to testing (Debian testing watch)
  • [2025-06-12] Accepted libtpms 0.9.2-3.2 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2023-05-21] Accepted libtpms 0.9.2-3.1~bpo11+1 (source) into bullseye-backports (Bastian Germann) (signed by: bage@debian.org)
  • [2023-03-13] libtpms 0.9.2-3.1 MIGRATED to testing (Debian testing watch)
  • [2023-03-10] Accepted libtpms 0.9.2-3.1~deb12u1 (source) into testing-proposed-updates (Salvatore Bonaccorso)
  • [2023-03-10] Accepted libtpms 0.9.2-3.1~deb12u1 (source) into testing-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2023-03-08] Accepted libtpms 0.9.2-3.1 (source) into unstable (Salvatore Bonaccorso)
  • [2022-08-22] Accepted libtpms 0.9.2-3~bpo11+1 (source amd64) into bullseye-backports, bullseye-backports (Debian FTP Masters) (signed by: bage@debian.org)
  • [2022-03-13] libtpms 0.9.2-3 MIGRATED to testing (Debian testing watch)
  • [2022-03-08] Accepted libtpms 0.9.2-3 (source) into unstable (Seunghun Han)
  • [2022-02-22] Accepted libtpms 0.9.2-2 (source) into unstable (Seunghun Han)
  • [2022-02-22] Accepted libtpms 0.9.2-1 (source amd64) into unstable (Seunghun Han)
  • [2022-02-04] Accepted libtpms 0.9.1-1 (source amd64) into unstable (Seunghun Han)
  • [2021-04-16] Accepted libtpms 0.8.2-1 (source amd64) into unstable (Seunghun Han)
  • [2020-09-02] libtpms REMOVED from testing (Debian testing watch)
  • [2020-08-11] Accepted libtpms 0.8.0~dev1-1.2 (source amd64) into unstable (Seunghun Han)
  • [2020-07-13] libtpms 0.8.0~dev1-1.1 MIGRATED to testing (Debian testing watch)
  • [2020-07-07] Accepted libtpms 0.8.0~dev1-1.1 (source) into unstable (Boyuan Yang)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.10.2-5ubuntu1
  • 1 bug (1 patch)
  • patches for 0.10.2-5ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing