AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty
Summary
| CVE | CVE-2026-6458 |
|---|---|
| State | PUBLISHED |
| Assigner | Caliptra |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-24 00:16:34 UTC |
| Updated | 2026-06-24 00:16:34 UTC |
| Description | Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of processed ciphertext. Ciphertext produced by that call may be modified without the tag reflecting the change. This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.1.0. |
Risk And Classification
Primary CVSS: v4.0 5.1 MEDIUM from b01ddd03-5ef6-483b-b2c5-acba77f1a554
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-325 | CWE-325 CWE-325 Missing Cryptographic Step
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | b01ddd03-5ef6-483b-b2c5-acba77f1a554 | Secondary | 5.1 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 5.1 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N |
CVSS v4.0 Breakdown
Attack Vector
AdjacentAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
NoneIntegrity
LowAvailability
NoneSub Conf.
LowSub Integrity
LowSub Availability
NoneCVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Caliptra | Core Runtime Firmware | affected 2.0.0 2.0.1 semver | Not specified |
| CNA | Caliptra | Core Runtime Firmware | affected 2.1.0 semver | Not specified |
| CNA | Caliptra | Core Runtime Firmware | unaffected 2.0.2 semver | Not specified |
| CNA | Caliptra | Core Runtime Firmware | unaffected 2.1.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-834g-h5x6-... | b01ddd03-5ef6-483b-b2c5-acba77f1a554 | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: NVIDIA Offensive Security Research (OSR) team (en)
There are currently no legacy QID mappings associated with this CVE.