PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108268 Privasys CVE debrief

CVE-2026-108268 debrief: Enclave OS Virtual RA-TLS certificates were not bound to the TLS session, allowing potential relay attacks. This issue is fixed in tdx-v0.2.43 and tdx-gpu-v0.6.27. The vulnerability impacts confidentiality and integrity of attested connections. Defenders should assess exposure and prioritize updates to prevent exploitation. The issue involves TDX/GPU RA-TLS certificate issuer omitting a value bound to the active TLS session, allowing an attacker with an enclave TLS private key to relay a genuine quote onto another connection.

Vendor
Privasys
Product
enclave-os-virtual
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-09
Original CVE updated
2026-10-09
Advisory published
2026-10-09
Advisory updated
2026-10-09

Who should care

Defenders of Enclave OS Virtual deployments should assess exposure and prioritize updating affected versions to prevent potential relay attacks. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for Enclave OS Virtual environments.

Why it matters

CVE-2026-108268 allows potential relay attacks against Enclave OS Virtual deployments prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, impacting confidentiality and integrity of attested connections.

  • Potential relay attacks against Enclave OS Virtual deployments
  • Need to verify and update affected deployments to prevent exploitation
  • Possible impact on confidentiality and integrity of attested connections

Technical summary

Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave.

Defensive priority

Defenders should prioritize verifying and updating affected Enclave OS Virtual deployments to prevent potential relay attacks.

Recommended defensive actions

  • Verify and update affected Enclave OS Virtual deployments to tdx-v0.2.43 or tdx-gpu-v0.6.27
  • Review and assess exposure of Enclave OS Virtual deployments
  • Monitor for potential relay attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, limited information is available on potential exploitation or victim impact. Defenders should verify and update affected Enclave OS Virtual deployments to tdx-v0.2.43 or tdx-gpu-v0.6.27. The source item and CVE record confirm the vulnerability but do not provide extensive details on exploitation or impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108268 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108268

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108268 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108268

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108268.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Privasys/enclave-os-virtual/commit/9a6be91e29f2b6738d0b77c33cd1ad5cd3d8a347

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Privasys/enclave-os-virtual/releases/tag/tdx-gpu-v0.6.27

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Privasys/enclave-os-virtual/releases/tag/tdx-v0.2.43

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://privasys.org/blog/binding-attestation-to-the-tls-session

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.