CVE-2025-23149
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-23149 is a vulnerability discovered in the Linux kernel's TPM (Trusted Platform Module) handling mechanism, identified on May 1, 2025. The vulnerability affects the TPM chip state verification process in the Linux kernel, specifically involving improper checking of TPMCHIPFLAG_SUSPENDED flag (NVD Database, Debian Tracker).

Technical details

The vulnerability occurs when the TPMCHIPFLAGSUSPENDED flag check is performed after tpmfindgetops() call, which can lead to an unexpected tpmchipstart() call while the system is suspended. This results in an unauthorized i2c transfer during system suspension, triggering warning messages and potential system instability. The issue manifests specifically in the TPM chip's state verification process (Wiz Database, Red Hat Portal).

Impact

When exploited, this vulnerability can cause unexpected system behavior during suspension states, particularly affecting TPM operations. The issue manifests as unauthorized I2C transfers during system suspension, which could potentially impact system stability and security mechanisms relying on TPM functionality. Red Hat has assigned this vulnerability a CVSS v3 Base Score of 5.5 (Red Hat Portal, Wiz Database).

Mitigation and workarounds

The fix involves ensuring that tpmchipstart() is not called inside tpmtrygetops() unless TPMCHIPFLAGSUSPENDED is explicitly unset. The patch ensures that tpmfindget_ops() returns NULL in failure cases. Fixed versions are available in various Linux distributions, including Debian sid (6.12.25-1) (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management