VU#431093: TCG TPM 2.0 referen... Note

VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks

Two vulnerabilities, CVE-2026-6726 and CVE-2026-6727, have been discovered in the TPM 2.0 reference implementation. CVE-2026-6727 is a timing side-channel flaw in RSA OAEP decryption. CVE-2026-6726 is an information leakage vulnerability related to falsified TPM keys. These issues require privileged local access to the TPM command interface to be exploited. Successful exploitation could allow an attacker to decrypt data encrypted to TPM-managed RSA keys. It may also enable the creation of fraudulent TPM 2.0 attestations using forged keys. The vulnerabilities are detailed in TCG advisories TCGVRT010 and TCGVRT0011. TPM vendors have addressed these flaws by releasing updated firmware and software. Users should apply these updates from their platform or TPM vendor. Cloud providers using software TPMs may have also deployed necessary patches. The overall impact varies based on TPM implementation and usage.