{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/431093#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nTwo vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation:\r\n\r\n1. **CVE-2026-6726** – Information leakage via falsified TPM keys.\r\n2. **CVE-2026-6727** – A timing side-channel vulnerability in RSA OAEP decryption.\r\n\r\nAn attacker with privileged access to a TPM command interface may be able to exploit these vulnerabilities by sending specially crafted TPM commands. Successful exploitation could allow the attacker to decrypt ciphertexts encrypted to affected TPM-managed RSA keys, including the RSA Endorsement Key (EK), or obtain credentials for falsified TPM keys, enabling forged TPM 2.0 attestations.\r\n These vulnerabilities are also documented by the Trusted Computing Group (TCG) in advisories - [**TCGVRT010 and TCGVRT0011**:](https://trustedcomputinggroup.org/about/security/#willa)\r\n\r\n### Description\r\nTrusted Platform Module (TPM) technology provides hardware-backed cryptographic services for modern computing platforms. TPMs are designed to resist tampering and may be implemented as discrete chips, integrated hardware, firmware-based TPMs (fTPMs), or software implementations used in cloud and virtualized environments.\r\nThe Trusted Computing Group (TCG) maintains the TPM specifications and publishes a reference implementation to assist vendors in developing TPM-compliant products.\r\n\r\nTwo vulnerabilities were identified in the TPM 2.0 reference implementation.\r\n\r\n**CVE-2026-6727** \r\nA timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations.\r\n\r\n**CVE-2026-6726**\r\nAn information leakage vulnerability could allow a privileged local attacker to obtain credentials from a TPM-aware Certificate Authority (CA) for a falsified TPM key, such as an Attestation Key (AK), DevID key, or TLS authentication key. This could enable the creation of fraudulent TPM 2.0 attestations using the forged key.\r\n\r\nBoth vulnerabilities require privileged access to the TPM command interface. Multiple vendors have released firmware and software updates incorporating fixes from the updated TPM 2.0 reference implementation.\r\n\r\n### Impact\r\n\r\nSuccessful exploitation requires privileged local access to a TPM command interface. Depending on the vulnerability exploited, an attacker may be able to:\r\n- Decrypt ciphertexts encrypted to the TPM-managed RS keys, including the RSA Endorsement Key (EK), , including credential blobs, import blobs, and session salts.\r\n- Obtain credentials for falsified TPM keys.\r\n- Produce fraudulent TPM 2.0 attestations that appear to originate from a legitimate TPM.\r\n\r\nThe overall impact depends on the affected TPM implementation and how TPM-based attestation and key management are used by the platform. \r\n\r\n### Solution\r\n\r\nThe vulnerabilities originate in the TPM 2.0 reference implementation, and TPM vendors have incorporated the corresponding fixes into updated firmware and software releases. Users should install TPM firmware updates, operating system updates, or software patches provided by their platform or TPM vendor.\r\n\r\nCloud providers using software-based TPM implementations may also have deployed updates. Customers should consult their cloud provider's guidance to determine whether any additional action is required. See the **Vendor Information** section for product-specific remediation guidance.\r\n\r\n## Acknowledgements\r\n\r\nThanks to security researchers Liran Perez, Zecharye Galitzky, Shai Sarfati, and Yanai Moyal from Intel for reporting these vulnerabilities.  Thanks to members of the Trusted Computing Group’s Vulnerability Response Team, TCG VRT, for working with CERT/CC towards this multi-party vulnerability disclosure. This document was written by Vijay Sarvepalli.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/431093"},{"url":"https://trustedcomputinggroup.org/about/security/","summary":"https://trustedcomputinggroup.org/about/security/"},{"url":"https://trustedcomputinggroup.org/resource/tpm-library-specification/","summary":"https://trustedcomputinggroup.org/resource/tpm-library-specification/"},{"url":"https://trustedcomputinggroup.org/resource/errata-for-tpm-library-specification-2-0/","summary":"https://trustedcomputinggroup.org/resource/errata-for-tpm-library-specification-2-0/"},{"url":"https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.pdf","summary":"https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.pdf"},{"url":"https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.pdf","summary":"https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.pdf"},{"url":"https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidance_V1.pdf","summary":"https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidance_V1.pdf"},{"url":"https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidance_V1.pdf","summary":"https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidance_V1.pdf"}],"title":"TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks","tracking":{"current_release_date":"2026-08-11T15:12:28+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.43"}},"id":"VU#431093","initial_release_date":"2026-08-11 15:12:28.872216+00:00","revision_history":[{"date":"2026-08-11T15:12:28+00:00","number":"1.20260811151228.1","summary":"Released on 2026-08-11T15:12:28+00:00"}],"status":"final","version":"1.20260811151228.1"}},"vulnerabilities":[{"title":"An information leakage vulnerability was reported in the TCG TPM 2.","notes":[{"category":"summary","text":"An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key.  See also TCG VRT0010"}],"cve":"CVE-2026-6726","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#431093"}],"product_status":{"known_affected":["CSAFPID-ffdf07b8-95a5-11f1-b41f-0214dffb1a89","CSAFPID-ffdf9048-95a5-11f1-b41f-0214dffb1a89"],"known_not_affected":["CSAFPID-ffdf264e-95a5-11f1-b41f-0214dffb1a89","CSAFPID-ffdf43ae-95a5-11f1-b41f-0214dffb1a89","CSAFPID-ffdf7752-95a5-11f1-b41f-0214dffb1a89"]}},{"title":"A timing side-channel vulnerability in RSA OAEP decryption was reported in the TCG TPM 2.","notes":[{"category":"summary","text":"A timing side-channel vulnerability in RSA OAEP decryption was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to decrypt ciphertexts (import blobs, credential blobs, and session salts) encrypted to the RSA Endorsement Key or falsify TPM 2.0 Attestation Keys."}],"cve":"CVE-2026-6727","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#431093"}],"product_status":{"known_affected":["CSAFPID-ffdfc3b0-95a5-11f1-b41f-0214dffb1a89","CSAFPID-ffe03e9e-95a5-11f1-b41f-0214dffb1a89"],"known_not_affected":["CSAFPID-ffdfdc9c-95a5-11f1-b41f-0214dffb1a89","CSAFPID-ffdff45c-95a5-11f1-b41f-0214dffb1a89","CSAFPID-ffe02666-95a5-11f1-b41f-0214dffb1a89"]}}],"product_tree":{"branches":[{"category":"vendor","name":"AMD","product":{"name":"AMD Products","product_id":"CSAFPID-ffdf07b8-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"Ampere Computing.","product":{"name":"Ampere Computing. Products","product_id":"CSAFPID-ffdf264e-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"Absolute Software","product":{"name":"Absolute Software Products","product_id":"CSAFPID-ffdf43ae-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"libtpms IBM sponsored","product":{"name":"libtpms IBM sponsored Products","product_id":"CSAFPID-ffdf5e98-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"Meta","product":{"name":"Meta Products","product_id":"CSAFPID-ffdf7752-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"Intel","product":{"name":"Intel Products","product_id":"CSAFPID-ffdf9048-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"AMD","product":{"name":"AMD Products","product_id":"CSAFPID-ffdfc3b0-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"Ampere Computing.","product":{"name":"Ampere Computing. Products","product_id":"CSAFPID-ffdfdc9c-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"Absolute Software","product":{"name":"Absolute Software Products","product_id":"CSAFPID-ffdff45c-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"libtpms IBM sponsored","product":{"name":"libtpms IBM sponsored Products","product_id":"CSAFPID-ffe00e92-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"Meta","product":{"name":"Meta Products","product_id":"CSAFPID-ffe02666-95a5-11f1-b41f-0214dffb1a89"}},{"category":"vendor","name":"Intel","product":{"name":"Intel Products","product_id":"CSAFPID-ffe03e9e-95a5-11f1-b41f-0214dffb1a89"}}]}}