PatchSiren

Trusted Computing Group CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Trusted Computing Group CVE published 2026-08-11

CVE-2026-6727

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation, which may allow a privileged local attacker to recover information and potentially decrypt ciphertexts encrypted to TPM-managed RSA keys. This could also enable the forgery of TPM 2.0 attestations under certain conditions. The vulnerability affects systems using TPM-managed RSA keys, including the RSA Endorsement Key (EK [truncated]

HIGH Trusted Computing Group CVE published 2026-08-11

CVE-2026-6726

A high-severity information leakage vulnerability was reported in the TCG TPM 2.0 reference code. A local attacker with elevated privileges could obtain a credential from a TPM-aware CA for a falsified TPM key and falsify other TPM 2.0 attestations with this key. This vulnerability affects TPM 2.0 deployments, particularly those using TPM-aware CA and relying on TPM 2.0 attestations for secure operations. [truncated]