CVE-2026-75900Disclosure

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead of sizeof(*bh), the actual struct size. This allows an undersized buffer to pass validation, causing a 2-byte heap overread on 64-bit systems (6 bytes on 32-bit) when accessing the totlen field. This may cause daemon termination on some platforms and leaks heap data to the log.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-19); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-19: 2Mentions · 2026-09-01: 1Technical Details · 2026-08-19: 208-1909-01
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-192
Disclosure2
2026-09-011
General1
Full discourse3 posts
  • 青柳 賢太朗|元プライム企業CTO/CMO→現在全グループ営業推進×AI@CTO_Aoyagi
    General

    株式会社エスプールのグループ会社である 株式会社CyberCrewは、当社所属ホワイトハッカーのSuraj Theekshanaが発見・報告した脆弱性「CVE-2026-75900」が、Red Hatの公式CVE情報に掲載されましたので、お知らせいたします。https://prtimes.jp/main/html/rd/p/000000327.000004500.html https://cyber.spool.co.jp/news/news13592/

    Post summary

    The notice informs readers that CVE-2026-75900, discovered by a white‑hacker, has been listed in Red Hat’s official CVE database, without additional technical or exploit details.

    11030454
    1.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75900 Out-of-Bounds Read in swtpm SWTPM_NVRAM_CheckHeader() Leads to Heap Overread and Data Leak https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75900

    Post summary

    This post announces CVE‑2026‑75900, detailing an out‑of‑bounds read in swtpm’s SWTPM_NVRAM_CheckHeader that can lead to heap overread and data leakage, without providing PoC, exploit code, patches, or evidence of active exploitation.

    00000108
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-75900 An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is … https://www.cve.org/CVERecord?id=CVE-2026-75900

    Post summary

    The post announces the discovery of an out‑of‑bounds read in swtpm’s SWTPM_NVRAM_CheckHeader function, providing brief technical details but no evidence of exploitation, PoC, or patch information.

    00000658
    58.0K followersView on X

Explore more