CVE-2026-6458

Source
https://cve.org/CVERecord?id=CVE-2026-6458
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6458.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6458
Aliases
  • GHSA-834g-h5x6-2hqr
Published
2026-06-23T23:49:44.591Z
Modified
2026-08-04T11:51:17.057977193Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
Details

Missing cryptographic step in Caliptra Core Firmware (aes256gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of processed ciphertext. Ciphertext produced by that call may be modified without the tag reflecting the change.

This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0.

Database specific
{
    "cwe_ids": [
        "CWE-325"
    ],
    "cna_assigner": "Caliptra",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6458.json"
}
References

Affected packages

Git / github.com/chipsalliance/caliptra-sw

Affected ranges

Type
GIT
Repo
https://github.com/chipsalliance/caliptra-sw
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.1"
        },
        {
            "introduced": "2.1.0"
        },
        {
            "last_affected": "2.1.0"
        }
    ]
}

Affected versions

2.*
2.1.0
fw-2.*
fw-2.0.0
release_v20251120_1-2.*
release_v20251120_1-2.x
release_v20251121_0-2.*
release_v20251121_0-2.x
release_v20251122_0-2.*
release_v20251122_0-2.x
release_v20251125_0-2.*
release_v20251125_0-2.x
release_v20251125_1-2.*
release_v20251125_1-2.x
release_v20251126_0-2.*
release_v20251126_0-2.x
release_v20251128_0-2.*
release_v20251128_0-2.x
release_v20251203_0-2.*
release_v20251203_0-2.x
release_v20251204_0-2.*
release_v20251204_0-2.x
release_v20260120_0-2.*
release_v20260120_0-2.0
release_v20260207_0-2.*
release_v20260207_0-2.0
release_v20260207_0-2.x
release_v20260207_1-2.*
release_v20260207_1-2.x
release_v20260208_0-2.*
release_v20260208_0-2.0
release_v20260209_0-2.*
release_v20260209_0-2.0
rom-2.*
rom-2.0.0
rom-2.0.1
rom-2.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6458.json"