CVE-2026-108268

Source
https://cve.org/CVERecord?id=CVE-2026-108268
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108268.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-108268
Aliases
  • GHSA-p5fp-g94g-g9m9
Published
2026-10-09T21:13:33Z
Modified
2026-10-11T02:46:57Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
enclave-os-virtual: RA-TLS challenge certificates were not bound to the TLS session
Details

Enclave OS Virtual runs container workloads inside confidential virtual machines with end-to-end attestation. Prior to tdx-v0.2.43 and tdx-gpu-v0.6.27, the TDX/GPU RA-TLS certificate issuer placed the certificate public-key hash and client nonce in quote ReportData but omitted a value bound to the active TLS session. An attacker who obtained an enclave TLS private key could relay a genuine quote onto another connection, causing a relying party to accept an attacker-terminated connection as the attested enclave. This issue is fixed in tdx-v0.2.43 and tdx-gpu-v0.6.27.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-346"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/108xxx/CVE-2026-108268.json"
}
References

Affected packages

Git / github.com/privasys/enclave-os-virtual

Affected ranges

Type
GIT
Repo
https://github.com/privasys/enclave-os-virtual
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "tdx-v0.2.43"
        },
        {
            "fixed": "tdx-gpu-v0.6.27"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

tdx-gpu-v0.*
tdx-gpu-v0.3.0
tdx-gpu-v0.3.1
tdx-gpu-v0.3.2
tdx-gpu-v0.3.4
tdx-gpu-v0.3.5
tdx-gpu-v0.3.6
tdx-gpu-v0.4.0
tdx-gpu-v0.5.0
tdx-gpu-v0.5.1
tdx-gpu-v0.5.2
tdx-gpu-v0.5.3
tdx-gpu-v0.5.4
tdx-gpu-v0.5.5
tdx-gpu-v0.6.0
tdx-gpu-v0.6.1
tdx-gpu-v0.6.10
tdx-gpu-v0.6.11
tdx-gpu-v0.6.12
tdx-gpu-v0.6.13
tdx-gpu-v0.6.14
tdx-gpu-v0.6.15
tdx-gpu-v0.6.16-dev
tdx-gpu-v0.6.17-dev
tdx-gpu-v0.6.18-dev
tdx-gpu-v0.6.19-dev
tdx-gpu-v0.6.2
tdx-gpu-v0.6.20
tdx-gpu-v0.6.20-dev
tdx-gpu-v0.6.21
tdx-gpu-v0.6.22
tdx-gpu-v0.6.23
tdx-gpu-v0.6.24
tdx-gpu-v0.6.25
tdx-gpu-v0.6.26-dev
tdx-gpu-v0.6.3
tdx-gpu-v0.6.4
tdx-gpu-v0.6.5
tdx-gpu-v0.6.6
tdx-gpu-v0.6.7
tdx-gpu-v0.6.8
tdx-gpu-v0.6.9
tdx-v0.*
tdx-v0.2.0
tdx-v0.2.1
tdx-v0.2.10
tdx-v0.2.11
tdx-v0.2.12
tdx-v0.2.13
tdx-v0.2.14
tdx-v0.2.15
tdx-v0.2.16
tdx-v0.2.17
tdx-v0.2.18
tdx-v0.2.18-dev
tdx-v0.2.19
tdx-v0.2.19-dev
tdx-v0.2.2
tdx-v0.2.20
tdx-v0.2.20-dev
tdx-v0.2.21-dev
tdx-v0.2.22-dev
tdx-v0.2.23-dev
tdx-v0.2.24-dev
tdx-v0.2.25-dev
tdx-v0.2.26-dev
tdx-v0.2.27-dev
tdx-v0.2.28
tdx-v0.2.29
tdx-v0.2.3
tdx-v0.2.30-dev
tdx-v0.2.31
tdx-v0.2.32
tdx-v0.2.32-dev
tdx-v0.2.33
tdx-v0.2.34
tdx-v0.2.35
tdx-v0.2.4
tdx-v0.2.5
tdx-v0.2.6
tdx-v0.2.7
tdx-v0.2.8
tdx-v0.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-108268.json"