Vulnerability in libtpms Affects OpenSSL Integration
CVE-2026-21444
What is CVE-2026-21444?
libtpms, a software library for emulating Trusted Platform Modules, contains a vulnerability that affects its integration with OpenSSL 3.x in versions 0.10.0 and 0.10.1. The issue arises when certain symmetric ciphers are utilized; instead of providing the last used initialization vector (IV) for encryption, the library incorrectly returns the initial IV. This erroneous behavior compromises the integrity of the encryption and decryption processes, potentially exposing sensitive data. The flaw necessitates an upgrade to version 0.10.2, which addresses the reported issue, as no workarounds are available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
libtpms >= 0.10.0, < 0.10.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
