CVE-2026-6458: AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
Missing cryptographic step in Caliptra Core Firmware (aes256gcmupdate module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of processed ciphertext. Ciphertext produced by that call may be modified without the tag reflecting the change.
This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Caliptra Core Firmware (aes_256_gcm_update module)to a version that resolves this vulnerability.Fixed in 2.0.1 - Upgrade
Upgrade
Core Runtime Firmwareto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6458?
The severity of CVE-2026-6458 is rated as medium with a CVSS score of 5.1.
How do I fix CVE-2026-6458?
To fix CVE-2026-6458, update the Caliptra Core Runtime Firmware to the latest version that addresses this vulnerability.
What software is affected by CVE-2026-6458?
CVE-2026-6458 affects the Caliptra Core Runtime Firmware (Caliptra).
What is the impact of CVE-2026-6458?
The impact of CVE-2026-6458 is that it results in an incorrect AES-256-GCM authentication tag when the Additional Authenticated Data (AAD) is empty.
When was CVE-2026-6458 published?
CVE-2026-6458 was published on June 23, 2026.