CVE Explorer
CVE-2026-6458
Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardware GHASH accumulator state is not saved after the first update call, causing the final tag to exclude the first batch of processed ciphertext. Ciphertext produced by that call may be modified without the tag reflecting the change.
This issue affects Core Runtime Firmware: from 2.0.0 through 2.0.1, 2.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://github.com/chipsalliance/caliptra-sw","defaultStatus":"unaffected","modules":["aes_256_gcm_update"],"packageName":"Core Runtime Firmware","product":"Core Runtime Firmware","vendor":"Caliptra","versions":[{"lessThanOrEqual":"2.0.1","status":"affected","version":"2.0.0","versionType":"semver"},{"status":"affected","version":"2.1.0","versionType":"semver"},{"status":"unaffected","version":"2.0.2","versionType":"semver"},{"status":"unaffected","version":"2.1.1","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e0acacbdf1aa094c15ab3a2615962f287046da4dba81ef9107d8e17211397f94 · sha256:a48d83ced63fb0fc… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":5.1,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e0acacbdf1aa094c15ab3a2615962f287046da4dba81ef9107d8e17211397f94 · sha256:a48d83ced63fb0fc… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-325","description":"CWE-325 Missing Cryptographic Step","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e0acacbdf1aa094c15ab3a2615962f287046da4dba81ef9107d8e17211397f94 · sha256:a48d83ced63fb0fc… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://github.com/chipsalliance/caliptra-sw/security/advisories/GHSA-834g-h5x6-2hqr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e0acacbdf1aa094c15ab3a2615962f287046da4dba81ef9107d8e17211397f94 · sha256:a48d83ced63fb0fc… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.