TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata 1.83 and advisory VRT0009 of TCG standard TPM2.0
https://kb.cert.org/vuls/id/282450
https://www.kb.cert.org/vuls/id/282450
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01209.html
https://www.cve.org/CVERecord?id=CVE-2025-49133
https://trustedcomputinggroup.org/wp-content/uploads/VRT0009-Advisory-FINAL.pdf
https://trustedcomputinggroup.org/wp-content/uploads/TPM2.0-Library-Spec-v1.83-Errata_v1_pub.pdf
https://trustedcomputinggroup.org/about/security/
https://github.com/stefanberger/libtpms/commit/04b2d8e9afc0a9b6bffe562a23e58c0de11532d1