Skip to content
SUSE Addresses Two Moderate Vulnerabilities in SWTPM and libtpms

SUSE Addresses Two Moderate Vulnerabilities in SWTPM and libtpms

First seen 28 Sep 2026, 19:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 20:08 UTC
  • •SUSE has patched two moderate vulnerabilities in SWTPM and libtpms.
  • •CVE-2026-75900 and CVE-2026-85769 are confirmed exploitable.
  • •Users should apply patches immediately to mitigate potential risks.

SUSE has released updates to address two moderate vulnerabilities affecting its SWTPM and libtpms components. The first, CVE-2026-75900, involves an out-of-bounds read in SWTPM due to a pointer and struct size mismatch, while CVE-2026-85769 pertains to a heap overflow in libtpms during TPM2 state unmarshalling. Both vulnerabilities were confirmed to be exploitable, with CISA advising users to apply the patches promptly. The updates are available for SUSE Linux Micro 6.0 across various architectures. The CVSS scores for the vulnerabilities are 6.1 and 6.8 respectively, indicating a moderate threat level. Users are encouraged to utilize SUSE's recommended installation methods to apply the patches. The vulnerabilities were publicly disclosed in August and September 2026, with proof-of-concept code available for CVE-2026-85769.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-19
CVE-2026-75900 published
An out-of-bounds read vulnerability in SWTPM was disclosed, affecting SUSE Linux Micro 6.0.
Linuxsecurity
2026-09-04
CVE-2026-85769 published
A heap overflow vulnerability in libtpms was disclosed, impacting SUSE Linux Micro 6.0.
Linuxsecurity
2026-09-22
Patch released for SWTPM and libtpms
SUSE released updates to fix the vulnerabilities, urging users to apply them using recommended methods.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-75900 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed