CVE Explorer
CVE-2026-32606
IncusOS is an immutable OS image dedicated to running Incus. Prior to 202603142010, the default configuration of systemd-cryptenroll as used by IncusOS through mkosi allows for an attacker with physical access to the machine to access the encrypted data without requiring any interaction by the system's owner or any tampering of Secure Boot state or kernel (UKI) boot image. That's because in this configuration, the LUKS key is made available by the TPM so long as the system has the expected PCR7
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"incus-os","vendor":"lxc","versions":[{"status":"affected","version":"< 202603142010"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6889b598dac6f587c57661310b24b07dda024357b288798e4240102a9f3c712d · sha256:e90efe0236d42b34… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"PHYSICAL","availabilityImpact":"HIGH","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6889b598dac6f587c57661310b24b07dda024357b288798e4240102a9f3c712d · sha256:e90efe0236d42b34… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-522","description":"CWE-522: Insufficiently Protected Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6889b598dac6f587c57661310b24b07dda024357b288798e4240102a9f3c712d · sha256:e90efe0236d42b34… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://discuss.linuxcontainers.org/t/potential-luks-encryption-bypass-through-filesystem-confusion/26348","tags":["x_refsource_MISC"],"url":"https://discuss.linuxcontainers.org/t/potential-luks-encryption-bypass-through-filesystem-confusion/26348"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6889b598dac6f587c57661310b24b07dda024357b288798e4240102a9f3c712d · sha256:e90efe0236d42b34… · /containers/cna/references/3
{"name":"https://github.com/lxc/incus-os/commit/e3b35f230d23443d27752eac27ebb2b22c957b75","tags":["x_refsource_MISC"],"url":"https://github.com/lxc/incus-os/commit/e3b35f230d23443d27752eac27ebb2b22c957b75"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6889b598dac6f587c57661310b24b07dda024357b288798e4240102a9f3c712d · sha256:e90efe0236d42b34… · /containers/cna/references/2
{"name":"https://github.com/lxc/incus-os/pull/954","tags":["x_refsource_MISC"],"url":"https://github.com/lxc/incus-os/pull/954"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6889b598dac6f587c57661310b24b07dda024357b288798e4240102a9f3c712d · sha256:e90efe0236d42b34… · /containers/cna/references/1
{"name":"https://github.com/lxc/incus-os/security/advisories/GHSA-wj2j-qwcf-cfcc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lxc/incus-os/security/advisories/GHSA-wj2j-qwcf-cfcc"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6889b598dac6f587c57661310b24b07dda024357b288798e4240102a9f3c712d · sha256:e90efe0236d42b34… · /containers/cna/references/0
{"name":"https://oddlama.org/blog/bypassing-disk-encryption-with-tpm2-unlock","tags":["x_refsource_MISC"],"url":"https://oddlama.org/blog/bypassing-disk-encryption-with-tpm2-unlock"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6889b598dac6f587c57661310b24b07dda024357b288798e4240102a9f3c712d · sha256:e90efe0236d42b34… · /containers/cna/references/4
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.