In the Linux kernel, the following vulnerability has been resolved: tpm: Cap the number of PCR banks tpm2_get_pcr_allocation() does not cap any upper limit for the number of banks. Cap the limit to eight banks so that out of bounds values coming from external I/O cause on only limited harm.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026011327-CVE-2025-71077-6e08@gregkh/T