PT-2026-1122 · Libtpms+1 · Libtpms+1

·

CVE-2026-21444

·

Published

2026-01-02

·

Updated

2026-03-25

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libtpms versions 0.10.0 through 0.10.1
Description libtpms, a library providing software emulation of a Trusted Platform Module, contains a flaw impacting data confidentiality. When integrated with OpenSSL 3.x, the library incorrectly returns the initial Initialization Vector (IV) instead of the last IV during symmetric cipher operations. This weakens encryption and decryption processes.
Recommendations Update to version 0.10.2 or later.

Exploit

Fix

Use of Insufficiently Random Values

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00914
CVE-2026-21444
GHSA-7JXR-4J3G-P34F
OPENSUSE-SU-2026:10422-1
OPENSUSE-SU-2026:20695-1
SUSE-SU-2026:21571-1
SUSE-SU-2026:21581-1

Affected Products

Openssl
Libtpms