---
id: CVE-2025-2884
title: >-
  TCG TPM2.0 Reference implementation's CryptHmacSign helper function is
  vulnerable to Out-of-Bounds read due to the lack of validation the signature
  scheme with the signature key's algorithm
summary: >-
  TCG TPM2.0 Reference implementation's CryptHmacSign helper function is
  vulnerable to Out-of-Bounds read due to the lack of validation the signature
  scheme with the signature key's algorithm. See Errata Revision 1.83 and
  advisory TCGVRT00…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
published: '2025-06-10'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-2884'
references:
  - url: >-
      https://github.com/stefanberger/libtpms/commit/04b2d8e9afc0a9b6bffe562a23e58c0de11532d1
    label: cret@cert.org
  - url: 'https://trustedcomputinggroup.org/about/security/'
    label: cret@cert.org
  - url: >-
      https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-v1.83-Errata_v1_pub.pdf
    label: cret@cert.org
  - url: >-
      https://trustedcomputinggroup.org/wp-content/uploads/VRT0009-Advisory-FINAL.pdf
    label: cret@cert.org
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-49133'
    label: cret@cert.org
  - url: >-
      https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01209.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.kb.cert.org/vuls/id/282450'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-628843.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
tags:
  - nvd
epss: 0.0025
epssPercentile: 0.16627
ingestedAt: '2026-08-11T16:47:03.580Z'
---

## Overview

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
