Timing Side-Channel Vulnerability in RSA OAEP Decryption for Trusted Platform Module by Trusted Computing Group
CVE-2026-6727
Currently unrated
What is CVE-2026-6727?
A vulnerability in the RSA OAEP decryption method within the Trusted Platform Module (TPM) allows a privileged local attacker with access to the TPM command interface to exploit timing discrepancies in operations. This exploitation may enable the recovery of sensitive information, such as ciphertexts encrypted with TPM-managed RSA keys, including the RSA Endorsement Key (EK). Additionally, there are potential risks of forgery regarding TPM 2.0 attestations under specific conditions. Immediate attention to system security is advised to mitigate risks associated with this vulnerability.
Affected Version(s)
TPM2.0 0
