CVE-2025-71077: tpm: Cap the number of PCR banks
Published Jan 13, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
tpm: Cap the number of PCR banks
tpm2getpcrallocation() does not cap any upper limit for the number of banks. Cap the limit to eight banks so that out of bounds values coming from external I/O cause on only limited harm.
Affected Software
17 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.119.3-3
Linux Linux kernel>=5.1.1<5.10.248
Linux Linux kernel>=5.11<5.15.198
Linux Linux kernel>=5.16<6.1.160
Linux Linux kernel>=6.2<6.6.120
Linux Linux kernel>=6.7<6.12.64
Linux Linux kernel>=6.13<6.18.3
Linux Linux kernel=5.1
Linux Linux kernel=6.19-rc1
Linux Linux kernel=6.19-rc2
Linux Linux kernel=6.19-rc3
Linux Linux kernel=6.19-rc4
Linux Linux kernel=6.19-rc5
Linux Linux kernel=6.19-rc6
Linux Linux kernel=6.19-rc7
Linux Linux kernel=6.19-rc8
Remediation
Event History
Jan 13, 2026
CVE Published
via MITRE·03:31 PM
Data Sourced
via MITRE·03:31 PM
Description
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityAffected Software
Jan 15, 2026
Data Sourced
via Microsoft·09:05 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·09:05 AM
Affected Software
Updated
via Microsoft·09:05 AM
DescriptionSeverity
Frequently Asked Questions
1
What level of access is required for exploitation?
The severity vector indicates local access and low privileges are required. No user interaction is required.
2
What should administrators do if they are responsible for affected systems?
Apply the available patch. The fix caps the PCR bank count at eight to limit harm from out-of-bounds values received through external I/O.