Junglewise Threat Intelligence

CVE-2026-6727: TPM 2.0 RSA OAEP timing side-channel in decryption

CVE-2026-6727 · Severity: medium · CVSS 5.9 · Published 2026-08-11

Executive brief

TPM 2.0 (Trusted Platform Module) devices contain a cryptographic vulnerability in how they decrypt RSA-encrypted data. A privileged local attacker with direct access to the TPM can exploit timing differences in the decryption process to recover sensitive encryption keys, including those protecting system credentials and attestation data. This could enable unauthorized decryption of sensitive data or forgery of system trust attestations.

Technical details

The vulnerability is a timing side-channel in the RSA OAEP decryption implementation within TPM 2.0 firmware. An attacker with privileged local access to the TPM command interface can measure response timing variations during decryption operations to recover information about RSA keys, particularly the RSA Endorsement Key (EK). By analyzing timing differences across multiple decryption attempts, the attacker can extract key material used to protect import blobs, credential blobs, and session salts. Under certain conditions, this can lead to forgery of TPM 2.0 attestations. The attack requires local privileged access to the TPM interface and does not require user interaction. Mitigation is pending availability of firmware patches from TPM manufacturers.

Affected products

  • Trusted Computing Group TPM 2.0

Timeline

  • 2026-08-11: disclosed

References