PT-2026-51610 · Unknown · Caliptra Core Runtime Firmware

CVE-2026-6458

·

Published

2026-06-23

·

Updated

2026-06-25

CVSS v4.0

5.1

Medium

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Caliptra Core Runtime Firmware versions 2.0.0 through 2.0.1 Caliptra Core Runtime Firmware version 2.1.0
Description A missing cryptographic step in the aes 256 gcm update module leads to an incorrect GCM authentication tag. When the streaming AES-256-GCM API is utilized with empty AAD (Additional Authenticated Data), the hardware GHASH accumulator state is not saved following the initial update call. Consequently, the final tag excludes the first batch of processed ciphertext, allowing the ciphertext from that call to be modified without the authentication tag reflecting the change.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6458
GHSA-834G-H5X6-2HQR

Affected Products

Caliptra Core Runtime Firmware