CVE-2026-72135: tpm: Make the TPM character devices non-seekable
In the Linux kernel, the following vulnerability has been resolved:
tpm: Make the TPM character devices non-seekable
The TPM character devices expose a sequential command/response interface, but their open handlers leave FMODEPREAD and FMODEPWRITE enabled.
After a command leaves a response pending, pread(fd, buf, 16, 0x1400) passes 0x1400 as off to tpmcommonread(). The transfer length is bounded by responselength, but the offset is used unchecked when forming databuffer + off. A sufficiently large offset therefore causes an out-of-bounds heap read through copytouser() and, if the copy succeeds, an out-of-bounds zero-write through the following memset().
Positional I/O does not provide coherent semantics for this interface. An arbitrary pread offset cannot represent how much of a response has been consumed sequentially. The write callback always stores a command at the start of databuffer, while pwrite() does not update file->fpos and can leave the sequential read cursor stale.
Call nonseekableopen() from both open handlers. This removes FMODEPREAD and FMODEPWRITE, causing positional reads and writes to fail with -ESPIPE before reaching the TPM callbacks, and explicitly marks the files non-seekable. Normal read() and write() continue to use the existing sequential fpos cursor, leaving the response state machine unchanged.
Tested on Linux 6.12 with KASAN and a swtpm TPM2 device:
- sequential partial reads returned the complete response - pread() and preadv() with offset 0x1400 returned -ESPIPE - pwrite() and pwritev() with offset zero returned -ESPIPE - the pending response remained intact after the rejected operations - a subsequent normal command/response cycle completed normally - no KASAN report was produced.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Update the Linux kernel so that the TPM character devices (tpm character devices) are made non-seekable by ensuring the open handlers do not leave FMODE_PREAD and FMODE_PWRITE enabled; this makes positional reads/writes (pread/pwrite with arbitrary offsets) fail with -ESPIPE before reaching TPM callbacks and prevents unchecked offset handling in tpm_common_read/tpm_common_write.
Linux kernel TPM character devices file mode flags (FMODE_PREAD and FMODE_PWRITE) / non-seekable open behavior = Disable positional I/O by leaving files non-seekable (no FMODE_PREAD/FMODE_PWRITE)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72135?
The severity of CVE-2026-72135 is rated as 47.
How do I fix CVE-2026-72135?
To fix CVE-2026-72135, ensure that your Linux kernel is updated to the latest version that addresses this vulnerability.
What are the implications of CVE-2026-72135?
The implications of CVE-2026-72135 include potential security risks related to the improper handling of TPM character devices.
What systems are affected by CVE-2026-72135?
CVE-2026-72135 affects systems running the vulnerable versions of the Linux kernel that utilize TPM character devices.
Is CVE-2026-72135 under active exploitation?
As of now, there are no confirmed reports of CVE-2026-72135 being actively exploited in the wild.