CVE-2026-6726

NameCVE-2026-6726
DescriptionAn information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libtpms (PTS)bookworm0.9.2-3.1+deb12u1fixed
bookworm (security)0.9.2-3.1~deb12u1fixed
trixie0.9.2-3.2fixed
forky, sid0.10.2-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libtpmssource(unstable)0.9.1-1

Notes

Fixed by: https://github.com/stefanberger/libtpms/commit/17255da54cf8354d02369f1323dc50cfb87e2bf4 (v0.9.0)
Fixed by: https://github.com/stefanberger/libtpms/commit/33a03986e0a09dde439985e0312d1c8fb3743aab (v0.8.5)
Fixed by: https://github.com/stefanberger/libtpms/commit/1196ab8a3d55eaadb1c8093cd102c4057eb7d9a6 (stable-0.10 branch)
Fixed by: https://github.com/stefanberger/libtpms/commit/854f547769251a8c5673e7ec5018e0ef363f4dd3 (stable-0.9 branch)
Consider already fixed with the changes applied in v0.8.5 and v0.9.0
https://groups.google.com/g/libtpms-announce/c/xB2PqSQRA_8

Search for package or bug name: Reporting problems