A timing side-channel vulnerability exists in the RSA OAEP decryption implementation, which may allow a privileged local attacker to recover information and potentially decrypt ciphertexts encrypted to TPM-managed RSA keys. This could also enable the forgery of TPM 2.0 attestations under certain conditions. The vulnerability affects systems using TPM-managed RSA keys, including the RSA Endorsement Key (EK [truncated]
HIGHTrusted Computing GroupCVE published 2026-08-11
A high-severity information leakage vulnerability was reported in the TCG TPM 2.0 reference code. A local attacker with elevated privileges could obtain a credential from a TPM-aware CA for a falsified TPM key and falsify other TPM 2.0 attestations with this key. This vulnerability affects TPM 2.0 deployments, particularly those using TPM-aware CA and relying on TPM 2.0 attestations for secure operations. [truncated]