30
30
30
30
30
35
35
35
35
35
30
35
30
30
30
30
30
30
30
35
35
35
35
35
35
30
35
30
30
35
35
VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
CERT/CC discloses two TPM 2.0 reference code flaws allowing RSA key decryption and forged TPM attestations via crafted commands.
CERT/CC published VU#431093 covering two vulnerabilities in the TCG TPM 2.0 reference implementation: CVE-2026-6726 (information leakage via falsified TPM keys) and CVE-2026-6727 (timing side-channel in RSA OAEP decryption). An attacker with privileged access to a TPM command interface could send crafted TPM commands to decrypt ciphertexts for affected TPM-managed RSA keys, including the RSA Endorsement Key, or obtain credentials enabling forged TPM 2.0 attestations. Remediation is tracked in TCGVRT010 and TCGVRT0011.
55
30
30
35
30
35
35
35
35