Cryptographic issues in libtpms - CVE-2026-21444

 

Cryptographic issues in libtpms - CVE-2026-21444

Published: January 5, 2026


Vulnerability identifier: #VU120909
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21444
CWE-ID: CWE-310
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to potentially decrypt data.

The vulnerability exists due to an error related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decryption steps.


Affected software

libtpms

How to mitigate CVE-2026-21444

Install updates from vendor's website.

libtpms - update to 0.10.2

External References

Related Security Bulletins