Insufficiently Protected Credentials Affecting github.com/lxc/incus-os/incus-osd/internal/storage package, versions <0.0.0-202603130128-e3b35f230d23


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMLXCINCUSOSINCUSOSDINTERNALSTORAGE-15763418
  • published25 Mar 2026
  • disclosed16 Mar 2026
  • creditU-00F8

Introduced: 16 Mar 2026

CVE-2026-32606  (opens in a new tab)
CWE-522  (opens in a new tab)

How to fix?

Upgrade github.com/lxc/incus-os/incus-osd/internal/storage to version 0.0.0-202603130128-e3b35f230d23 or higher.

Overview

Affected versions of this package are vulnerable to Insufficiently Protected Credentials due to insufficient policy enforcement in the Trusted Platform Module (TPM) during the disk decryption process. An attacker can gain unauthorized access to encrypted data by physically replacing the root partition with a controlled partition and leveraging the system's default boot process to extract encryption keys.

CVSS Base Scores

version 4.0
version 3.1