Description
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.
Published: 2026-08-11
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A timing side‑channel exists in the RSA OAEP decryption routine of TPM 2.0. By measuring decryption durations, an attacker can recover information sufficient to decrypt ciphertexts that target TPM‑managed RSA keys, such as the Endorsement Key, import blobs, credential blobs, and session salts. The disclosed impact includes exposure of sensitive data and, under certain conditions, the forging of TPM attestations, thereby undermining integrity and authenticity of boot and trust chain data.

Affected Systems

The flaw affects all TPM 2.0 devices and software that implement the RSA OAEP decryption routine. No vendor‑specific version details are disclosed in the CNA data, so any TPM 2.0 implementation may be susceptible unless fixed by firmware or software updates.

Risk and Exploitability

The vulnerability is exploitable only by a privileged local actor who can interact with the TPM command interface. The EPSS score is <1% and the CVSS score of 5.9 indicates moderate severity. It is not listed in the CISA KEV catalog. The severity potential is high because it enables extraction of critical keys and may let an attacker forge attestations. The lack of a publicly disclosed exploit makes the actual exploitation probability uncertain, but the capability demonstrated by the side‑channel is significant for attackers with local access.

Generated by OpenCVE AI on August 13, 2026 at 04:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest TPM 2.0 firmware or software update that addresses the RSA OAEP timing side‑channel defect.
  • Configure the system so that only trusted, privileged processes have access to the TPM command interface; limit physical and remote interfaces when possible.
  • Audit TPM command usage and monitor decryption timing for abnormal patterns that could indicate an ongoing exploitation attempt; revoke or rotate keys that may have been compromised.

Generated by OpenCVE AI on August 13, 2026 at 04:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Trustedcomputinggroup
Trustedcomputinggroup tpm2.0
Vendors & Products Trustedcomputinggroup
Trustedcomputinggroup tpm2.0

Thu, 13 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1023

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-208
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1023

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.
Title CVE-2026-6727
References

Subscriptions

Trustedcomputinggroup Tpm2.0
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-08-12T18:41:28.456Z

Reserved: 2026-04-20T21:18:19.891Z

Link: CVE-2026-6727

cve-icon Vulnrichment

Updated: 2026-08-12T18:41:15.556Z

cve-icon NVD

Status : Received

Published: 2026-08-11T16:17:34.503

Modified: 2026-08-12T19:17:54.567

Link: CVE-2026-6727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:19Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy