Executive brief
The Linux kernel's Trusted Platform Module (TPM) character device interface allows applications to communicate with the system's TPM chip. A flaw in the device handlers incorrectly permitted positional I/O operations (pread) with large offsets, enabling attackers to read memory beyond the response buffer and potentially leak sensitive data from kernel memory. This could expose cryptographic keys or other privileged information stored in the kernel.
Technical details
The vulnerability is a heap out-of-bounds read in the TPM character device driver (tpm_common_read). The open handlers leave FMODE_PREAD and FMODE_PWRITE flags enabled despite the interface being sequential only. An attacker can call pread() with an arbitrary offset (e.g., 0x1400) on an open TPM device file; the offset is used unchecked when calculating data_buffer + *off, causing copy_to_user() to leak kernel heap data beyond the intended response buffer. No authentication is required—only an open file descriptor to the TPM device. The fix disables positional I/O by calling nonseekable_open() from both TPM open handlers, causing pread/pwrite to fail with -ESPIPE before reaching the vulnerable code path.
Affected products
- Linux Linux kernel 6.12 and likely earlier versions
Timeline
- 2026-08-15: disclosed: CVE-2026-72135 published