Firmware Updates for LetsTrust-TPMs (Again!) (Blog Entry Update)
Hi Folks!
### Update 17th August 2026
Infineon informed about the latest TPM Updates, which was mentioned here in March 2026:
https://www.infineon.com/product-information/tpm-update
### 11th March 2026
Infineon has released a new update files for all TPMs.
This also means that ALL LetsTrust-TPMs can now be updated.
All delivered LetsTrust TPMs with the SLB-9670 had firmware 7.85, the update to 7.87 is available.
All delivered LetsTrust TPMs with the SLB-9672 had firmware 15.23 or higher.
Since December 2024 LetsTrust-TPM has been delivered with firmware 15.24.
Since March 2026 all LetsTrust will be delivered with latest firmware 15.25.
The following applies to both chips: All data remains on the TPM. The update only improves stability and fixes issues.
For the update tool and the relevant files you only need a "MyInfineon" account, which you can get by registering with a single-face email.
The update file itself is a binary blob, the Linux update tool is in c-source files and therefore still needs to be built.
The Tool, functional for all Infineon TPMs:
https://www.infineon.com/cms/en/product/security-smart-card-solutions/optiga-embedded-security-solutions/optiga-tpm/slb-9670vq2.0/#!?fileId=8ac78c8c95d1335f019600fccc6b6574
Update binary blob for SLB9670 FW 7.8x to FW 7.87:
https://www.infineon.com/document-promo/infineon-ifxtpmupdate-slb9670-v7.66-86-to-v7.87.19691.2.zip-firmware-en_e747c60a-1907-42a0-a9ee-4f5be72882e4
Update binary blob for SLB9672 FW 15.2x to FW 15.25:
https://www.infineon.com/gated/infineon-ifxtpmupdate-slb9672-v15.25.18954.0-r1-software-en_ccdeb0af-50c8-4962-962d-7f78e6a642bc
All LetsTrust-TPMs from 10th March 2026 will be delivered with firmware 15.25.
Bye for now,
Paul
PS: After an TPM-Update, the chip needs a Power-cycle OR a Reset-Cycle, with this script you can reset the TPM via GPIO: https://github.com/PaulKissinger/LetsTrust/blob/master/Scripts/TPM_reset_with_GPIO.sh
PSS: The Linux Update tool do not support the LetsTrust-TPM2Go, i'll try to provide a solution for that.
### Update 17th August 2026
Infineon informed about the latest TPM Updates, which was mentioned here in March 2026:
Aug 2026 - A certified firmware update for the OPTIGA™ TPM SLB 9672/9673 is available
It is Infineon’s policy to reflect state-of-the-art in security solutions. This includes consideration of new findings in upcoming software and product updates.
Following this policy, a firmware update has been released that covers the Trusted Computing Group finding VRT0010 (CVE-2026-6726).
This update also covers the Trusted Computing Group finding VRT0009 (CVE-2025-2884) as well as an adaptation of the crypto library function used for ECDSA for enhanced protection against advanced side channel attacks already contained in a previous firmware update.
[...]
https://www.infineon.com/product-information/tpm-update
### 11th March 2026
Infineon has released a new update files for all TPMs.
This also means that ALL LetsTrust-TPMs can now be updated.
All delivered LetsTrust TPMs with the SLB-9670 had firmware 7.85, the update to 7.87 is available.
All delivered LetsTrust TPMs with the SLB-9672 had firmware 15.23 or higher.
Since December 2024 LetsTrust-TPM has been delivered with firmware 15.24.
Since March 2026 all LetsTrust will be delivered with latest firmware 15.25.
The following applies to both chips: All data remains on the TPM. The update only improves stability and fixes issues.
For the update tool and the relevant files you only need a "MyInfineon" account, which you can get by registering with a single-face email.
The update file itself is a binary blob, the Linux update tool is in c-source files and therefore still needs to be built.
The Tool, functional for all Infineon TPMs:
https://www.infineon.com/cms/en/product/security-smart-card-solutions/optiga-embedded-security-solutions/optiga-tpm/slb-9670vq2.0/#!?fileId=8ac78c8c95d1335f019600fccc6b6574
Update binary blob for SLB9670 FW 7.8x to FW 7.87:
https://www.infineon.com/document-promo/infineon-ifxtpmupdate-slb9670-v7.66-86-to-v7.87.19691.2.zip-firmware-en_e747c60a-1907-42a0-a9ee-4f5be72882e4
Update binary blob for SLB9672 FW 15.2x to FW 15.25:
https://www.infineon.com/gated/infineon-ifxtpmupdate-slb9672-v15.25.18954.0-r1-software-en_ccdeb0af-50c8-4962-962d-7f78e6a642bc
All LetsTrust-TPMs from 10th March 2026 will be delivered with firmware 15.25.
Bye for now,
Paul
PS: After an TPM-Update, the chip needs a Power-cycle OR a Reset-Cycle, with this script you can reset the TPM via GPIO: https://github.com/PaulKissinger/LetsTrust/blob/master/Scripts/TPM_reset_with_GPIO.sh
PSS: The Linux Update tool do not support the LetsTrust-TPM2Go, i'll try to provide a solution for that.


