CVE-2026-6727 Affecting libtpms package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.19% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-LIBTPMS-18677186
  • published12 Aug 2026
  • disclosed11 Aug 2026

Introduced: 11 Aug 2026

NewCVE-2026-6727  (opens in a new tab)

How to fix?

There is no fixed version for Debian:unstable libtpms.

NVD Description

Note: Versions mentioned in the description apply only to the upstream libtpms package and not the libtpms package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.