<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T14:30:54.311072+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-38804</id>
    <title>EUVD-2026-38804</title>
    <updated>2026-10-08T14:30:54.374744+00:00</updated>
    <content>EUVD-2026-38804</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-38804"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8918</id>
    <title>fkie_cve-2020-8918</title>
    <updated>2026-10-08T14:30:54.374784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An improperly initialized 'migrationAuth' value in Google's go-tpm TPM1.2 library versions prior to 0.3.0 can lead an eavesdropping attacker to discover the auth value for a key created with CreateWrapKey. An attacker listening in on the channel can collect both 'encUsageAuth' and 'encMigrationAuth', and then can calculate 'usageAuth ^ encMigrationAuth' as the 'migrationAuth' can be guessed for all keys created with CreateWrapKey. TPM2.0 is not impacted by this. We recommend updating your library to 0.3.0 or later, or, if you cannot update, to call CreateWrapKey with a random 20-byte value for 'migrationAuth'.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-8918"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5x29-3hr9-6wpw</id>
    <title>GHSA-5x29-3hr9-6wpw — TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm</title>
    <updated>2026-10-08T14:30:54.374824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/google/go-tpm</p>
<p>### Impact
TPM 2.0 users are unaffected by this issue.</p>
<p>An adversary eavesdropping on the TPM 1.2 transport path can calculate `usageAuth` for a key created with CreateWrapKey, even though this value is encrypted as part of the TPM 1.2 command protocol.</p>
<p>The TPM 1.2 CreateWrapKey command accepts two secrets: `usageAuth` and `migrationAuth`. The ADIP protocol ([TPM 1.2 specification, part 1, section 13.4](https://trustedcomputinggroup.org/wp-content/uploads/TPM-Main-Part-1-Design-Principles_v1.2_rev116_01032011.pdf)) calls for these values to be encrypted with two different XOR keys. Due to a bug in go-tpm prior to version 0.3.0, both `usageAuth` and `migrationAuth` are encrypted with the same XOR keystream. This allows an adversary to XOR `encUsageAuth` and `encMigrationAuth` together to calculate `usageAuth ^ encMigrationAuth`. Since `migrationAuth` is moot for all keys created with go-tpm's `CreateWrapKey` (since all keys created with this function are marked non-migratable), an adversary may guess or know (from code/binary inspection) that `migrationAuth` is all 0x00 bytes or some other fixed value. Such an adversary can then calculate `usageAuth` and use this value later to improperly use the created key, unbeknownst to the creator of the key.</p>
<p>### Patches
Fixed in go-tpm version 0.3.0.</p>
<p>### Workarounds</p>
<p>- TPM 2.0 users: No workaround needed. This issue only affects TPM 1.2 users.
- TPM 1.2 users: Call CreateWrapKey with a random 20-byte value for `migrationAuth`, even t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5x29-3hr9-6wpw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-8918</id>
    <title>gsd-2020-8918</title>
    <updated>2026-10-08T14:30:54.374880+00:00</updated>
    <content>gsd-2020-8918</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-8918"/>
  </entry>
</feed>
