CVE-2026-6726
Publication date 13 August 2026
Last updated 14 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| libtpms | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.9 · High
Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-6726
- https://groups.google.com/g/libtpms-announce/c/xB2PqSQRA_8
- https://trustedcomputinggroup.org/resource/errata-for-tpm-library-specification-2-0/
- https://trustedcomputinggroup.org/wp-content/uploads/Extended-vrt0010-11-guidance_V1.pdf
- https://trustedcomputinggroup.org/wp-content/uploads/VRT0010-Advisory_Final-1.pdf