CVE-2026-21444 is a medium-severity vulnerability affecting libtpms versions 0.10.0 and 0.10.1, a software emulation library for Trusted Platform Modules. The flaw, specifically when integrated with OpenSSL 3.x, causes the library to incorrectly return the initial initialization vector (IV) instead of the last IV for certain symmetric ciphers, weakening subsequent encryption and decryption. This vulnerability has a CVSS score of 5.5, indicating a local attack vector with low complexity, requiring local privileges, and primarily impacting data confidentiality. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has received some community discussion and media coverage, including mention in a Microsoft Patch Tuesday article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.10.0, < 0.10.2CPE matchmatch criteria | cpe:2.3:a:libtpms_project:libtpms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.