PT-2026-1122 · Libtpms+1 · Libtpms+1
Stefanberger
·
Published
2026-01-02
·
Updated
2026-03-25
·
CVE-2026-21444
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
libtpms versions 0.10.0 through 0.10.1
Description
libtpms, a library providing software emulation of a Trusted Platform Module, contains a flaw impacting data confidentiality. When integrated with OpenSSL 3.x, the library incorrectly returns the initial Initialization Vector (IV) instead of the last IV during symmetric cipher operations. This weakens encryption and decryption processes.
Recommendations
Update to version 0.10.2 or later.
Exploit
Fix
Use of Insufficiently Random Values
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openssl
Libtpms