CVE-2026-75900

EUVD-2026-62363
An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, causing a 2-byte heap overread on 64-bit systems (6 bytes on 32-bit) when accessing the totlen field. This may cause daemon termination on some platforms and leaks heap data to the log.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.24%
Debian logo
Debian Releases
Debian Product
Codename
swtpm
bookworm
postponed
forky
0.10.2-1
fixed
sid
0.10.2-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
swtpm
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
swtpm
Azure Linux 3.0
0:0.8.1-6.azl3
fixed