VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
Brief
Overview
Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2. 0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption. An attacker with privileged access to a TPM command interface may be able to exploit these vulnerabilities by sending specially crafted TPM commands.
Successful exploitation could allow the attacker to decrypt ciphertexts encrypted to affected TPM-managed RSA keys, including the RSA Endorsement Key (EK), or obtain credentials for falsified TPM keys, enabling forged TPM 2. 0 attestations. TCGVRT010 and TCGVRT0011: Description Trusted Platform Module (TPM) technology provides hardware-backed cryptographic services for modern computing platforms.
