CVE-2026-85769 is an out-of-bounds heap read vulnerability in libtpms TPM 2.0 state unmarshalling. During restoration of TPM state, such as virtual-machine startup or migration/state restore, an attacker-controlled malformed state blob can specify an oversized skip-block length. libtpms fails to validate that length against the remaining input-buffer size, permitting an internal signed size counter to become negative. A subsequent unsafe signed-to-unsigned conversion bypasses a bounds check and causes parsing to read beyond the heap buffer containing the state data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This four-file repository contains a standalone C proof of concept, documentation, an MIT license, and ignore rules. Its sole code file, poc_f3.c, links against libtpms and OpenSSL. In gen mode it initializes a TPM 2.0 instance and exports valid permanent and volatile state blobs. In test mode it reads those blobs, mutates the ORDERLY_DATA optional-block trailer in the volatile blob using caller-supplied offset and block size values, recomputes the unauthenticated SHA-1 trailer, and restores the permanent then forged volatile state through TPMLIB_SetState. The targeted flaw is CVE-2026-85769: block_skip_read() subtracts an attacker-controlled UINT16 optional-block length from a signed remaining-size counter without first checking bounds; later checks cast the negative counter to UINT32, permitting parsing beyond the heap allocation. The documented practical effect is a heap-buffer-overflow read and process abort/denial of service, especially relevant where swtpm/libtpms state blobs are restored during migration. The code makes no network requests and contains no remote callback, shell payload, persistence, or data-theft behavior.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An out-of-bounds read denial-of-service vulnerability in libtpms TPM 2.0 state restoration. A malformed state blob can trigger unsafe length handling and signed-to-unsigned conversion, crashing a host process such as swtpm and disrupting the dependent virtual machine.
An availability-impacting vulnerability in libtpms packages, with a CVSS v3 vector indicating local-adjacent attack access, low complexity, no privileges or user interaction required, and high impact to availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.