CVE-2025-71077
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71077 is a denial-of-service vulnerability in the Linux kernel's TPM (Trusted Platform Module) subsystem, specifically in the tpm2_get_pcr_allocation() function, which fails to enforce an upper limit on the number of PCR (Platform Configuration Register) banks. This allows out-of-bounds values from external I/O to cause unbounded resource allocation. The vulnerability was published on January 13, 2026, and affects Linux kernel versions from 5.1 through multiple stable branches up to 6.18.x. It carries a CVSS v3.1 base score of 5.5 (Medium), requiring local access and low privileges (Feedly).

Technical details

The root cause is the absence of an upper-bound check in tpm2_get_pcr_allocation() when reading the number of PCR banks from external I/O (i.e., the TPM hardware or firmware). An attacker or malicious device can supply an excessively large bank count, causing the kernel to allocate unbounded memory. The fix caps the maximum number of PCR banks to eight, limiting the harm from out-of-bounds values. NVD classifies this as CWE-noinfo (Insufficient Information), though the behavior is consistent with improper input validation (CWE-20) from an untrusted hardware interface. The attack vector is local, requires low privileges, and no user interaction (Feedly).

Impact

Successful exploitation results in a denial-of-service condition through memory exhaustion, potentially causing system hangs or complete service unavailability. There is no confidentiality or integrity impact — the vulnerability is limited to availability. Systems with TPM 2.0 hardware and affected kernel versions are at risk, particularly where low-privileged local users have access (Feedly).

Mitigation and workarounds

Apply the available kernel patches for the affected version range. Fixed versions include: 5.10.248, 5.15.198, 6.1.160, 6.6.120, 6.12.64, 6.18.3, and 6.19-rc1. Multiple patch commits are available on kernel.org (e.g., 275c686f, 858344bc, 8ceee728, b6949216, ceb70d31, d8848165, faf07e61). Downstream distributions including Debian, Ubuntu (USN-8177-1, USN-8183-1, USN-8245-1, USN-8257-1), Amazon Linux 2, and Oracle Linux have also released updated packages. As a workaround where patching is not immediately possible, restrict local user access to systems with TPM hardware (Feedly, Ubuntu Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64557NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-selftests-internal
NoNoJul 29, 2026
CVE-2026-64556NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-devel
NoNoJul 29, 2026
CVE-2026-64555NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-fde-6.14
NoNoJul 27, 2026
CVE-2026-64554NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-gcp-6.14
NoYesJul 27, 2026
CVE-2026-64553NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-debug-modules-internal
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management