<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:ibm:libtpms:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aibmlibtpms/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 19:34:58 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aibmlibtpms/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in libtpms</title><link>https://feed.craftedsignal.io/briefs/2026-09-libtpms-dos/</link><pubDate>Tue, 08 Sep 2026 19:34:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-libtpms-dos/</guid><description>A vulnerability in libtpms (CVE-2024-0230) allows an attacker on an adjacent network to trigger a denial of service condition, potentially leading to service instability.</description><content:encoded><![CDATA[<p>A vulnerability has been identified in libtpms, a library providing software emulation of a Trusted Platform Module (TPM). The flaw, tracked as CVE-2024-0230, allows an unauthenticated attacker located on an adjacent network to cause a denial of service (DoS) condition. This vulnerability is triggered by improper processing of specific requests sent to the library, which can lead to system instability or service disruption for applications relying on libtpms for TPM functionality. Because the attack requires access to an adjacent network, the impact is primarily relevant to hypervisors, virtualization hosts, or container environments utilizing emulated TPMs where network segmentation might be bypassed or misconfigured. Organizations using virtualization stacks that incorporate libtpms should prioritize evaluating their exposure and applying updates provided by their distribution or vendor.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability impacts the availability of systems and services that depend on libtpms. A successful exploit results in a denial of service, forcing a restart or crash of the affected TPM-reliant component. This is particularly concerning for cloud infrastructure providers or high-density virtualization environments where a single host service failure could disrupt multiple hosted workloads.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor virtualization host logs for unexpected service restarts of TPM-related processes.</li>
<li>Apply the latest security updates for libtpms provided by your Linux distribution maintainer to address CVE-2024-0230.</li>
<li>Review network segmentation policies to ensure that management interfaces or virtualization backends are not exposed to untrusted adjacent network segments.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>virtualization</category></item></channel></rss>