Skip to content
Threat Feed
low advisory

Denial of Service Vulnerability in libtpms

A vulnerability in libtpms (CVE-2024-0230) allows an attacker on an adjacent network to trigger a denial of service condition, potentially leading to service instability.

CVE search metadata

CVE search record: CVE-2024-0230. Severity: low. CVSS: 2.4. EPSS: 1.22%. KEV: no. Product: libtpms. Brief: Denial of Service Vulnerability in libtpms. Brief link: https://feed.craftedsignal.io/briefs/2026-09-libtpms-dos/

A vulnerability has been identified in libtpms, a library providing software emulation of a Trusted Platform Module (TPM). The flaw, tracked as CVE-2024-0230, allows an unauthenticated attacker located on an adjacent network to cause a denial of service (DoS) condition. This vulnerability is triggered by improper processing of specific requests sent to the library, which can lead to system instability or service disruption for applications relying on libtpms for TPM functionality. Because the attack requires access to an adjacent network, the impact is primarily relevant to hypervisors, virtualization hosts, or container environments utilizing emulated TPMs where network segmentation might be bypassed or misconfigured. Organizations using virtualization stacks that incorporate libtpms should prioritize evaluating their exposure and applying updates provided by their distribution or vendor.

Impact

The vulnerability impacts the availability of systems and services that depend on libtpms. A successful exploit results in a denial of service, forcing a restart or crash of the affected TPM-reliant component. This is particularly concerning for cloud infrastructure providers or high-density virtualization environments where a single host service failure could disrupt multiple hosted workloads.

Recommendation

  • Monitor virtualization host logs for unexpected service restarts of TPM-related processes.
  • Apply the latest security updates for libtpms provided by your Linux distribution maintainer to address CVE-2024-0230.
  • Review network segmentation policies to ensure that management interfaces or virtualization backends are not exposed to untrusted adjacent network segments.

Mitigations

Patch libtpms to the version provided by the vendor or distribution package maintainer

immediate IT Operations

CVE-2024-0230