Vulnerability in libtpms Affects OpenSSL Integration
CVE-2026-21444

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
2 January 2026

What is CVE-2026-21444?

libtpms, a software library for emulating Trusted Platform Modules, contains a vulnerability that affects its integration with OpenSSL 3.x in versions 0.10.0 and 0.10.1. The issue arises when certain symmetric ciphers are utilized; instead of providing the last used initialization vector (IV) for encryption, the library incorrectly returns the initial IV. This erroneous behavior compromises the integrity of the encryption and decryption processes, potentially exposing sensitive data. The flaw necessitates an upgrade to version 0.10.2, which addresses the reported issue, as no workarounds are available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

libtpms >= 0.10.0, < 0.10.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.