Index out-of-bounds panic via crafted AK certificate with empty EKU in TPM device attestation
Fixed in: v0.30.0
patched
details
Finding IDs
F-SMALLSTEP-AK-EKU-001
CVE
CVE-2026-40097
GHSA
GHSA-9qq8-cgcv-qmc9
Status
patched
Fixed in
v0.30.0
Recorded credit
Oleh Konko (@1seal)
Note
GHSA-9qq8-cgcv-qmc9
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVE registry state
PUBLISHED
CVE state checked
Upstream title
Index out-of-bounds panic via crafted AK certificate with empty EKU in TPM device attestation
Upstream CWE
CWE-129
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
@1seal: reporter (accepted)
F-SMALLSTEP-AK-EKU-001: Input / state handling. An empty EKU input reaches a panic, not an established authorization bypass. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
TPM attestation EKU panic. public fix PR #2569, first released in v0.30.0. GHSA-9qq8-cgcv-qmc9 / CVE-2026-40097 published.
F-SMALLSTEP-AK-EKU-001: Input / state handling. An empty EKU input reaches a panic, not an established authorization bypass. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.