PatchSiren cyber security CVE debrief
CVE-2026-108268 Privasys CVE debrief
CVE-2026-108268 debrief: Enclave OS Virtual RA-TLS certificates were not bound to the TLS session, allowing potential relay attacks. This issue is fixed in tdx-v0.2.43 and tdx-gpu-v0.6.27. The vulnerability impacts confidentiality and integrity of attested connections. Defenders should assess exposure and prioritize updates to prevent exploitation. The issue involves TDX/GPU RA-TLS certificate issuer omitting a value bound to the active TLS session, allowing an attacker with an enclave TLS private key to relay a genuine quote onto another connection.
- Vendor
- Privasys
- Product
- enclave-os-virtual
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-09
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-09
- Advisory updated
- 2026-10-09
Who should care
Defenders of Enclave OS Virtual deployments should assess exposure and prioritize updating affected versions to prevent potential relay attacks. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for Enclave OS Virtual environments.
Why it matters
CVE-2026-108268 allows potential relay attacks against Enclave OS Virtual deployments prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, impacting confidentiality and integrity of attested connections.
- Potential relay attacks against Enclave OS Virtual deployments
- Need to verify and update affected deployments to prevent exploitation
- Possible impact on confidentiality and integrity of attested connections
Technical summary
Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave.
Defensive priority
Defenders should prioritize verifying and updating affected Enclave OS Virtual deployments to prevent potential relay attacks.
Recommended defensive actions
- Verify and update affected Enclave OS Virtual deployments to tdx-v0.2.43 or tdx-gpu-v0.6.27
- Review and assess exposure of Enclave OS Virtual deployments
- Monitor for potential relay attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and fixed versions. However, limited information is available on potential exploitation or victim impact. Defenders should verify and update affected Enclave OS Virtual deployments to tdx-v0.2.43 or tdx-gpu-v0.6.27. The source item and CVE record confirm the vulnerability but do not provide extensive details on exploitation or impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108268 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108268
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108268 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108268
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108268.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Privasys/enclave-os-virtual/security/advisories/GHSA-p5fp-g94g-g9m9
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/Privasys/enclave-os-virtual/commit/9a6be91e29f2b6738d0b77c33cd1ad5cd3d8a347
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/Privasys/enclave-os-virtual/releases/tag/tdx-gpu-v0.6.27
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/Privasys/enclave-os-virtual/releases/tag/tdx-v0.2.43
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://privasys.org/blog/binding-attestation-to-the-tls-session
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.