VDB

DEBIAN-CVE-2026-32953

DEBIAN-CVE-2026-32953 PUBLISHED CVSS 4.599999904632568 MEDIUM

Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the tkeyclient Go module which causes 1 out of every 256 User Supplied Secrets (USS) to be silently ignored, producing the same Compound Device Identifier (CDI)—and thus the same key material—as if no USS is provided. This happens because a buffer index error overwrites the USS-enabled boolean with the first byte of the USS digest, so any USS whose hash starts with 0x00 is effectively discarded. This issue has been fixed in version 1.3.0. Users unable to upgrade immediately should switch to a USS whose hash does not begin with a zero byte.

Risk Scores

CVSS 3.1
4.599999904632568
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:13golang-github-tillitis-tkeyclient1.3.1-1, 1.2.0-2, 1.2.0-2~exp0
Debian:14golang-github-tillitis-tkeyclient1.1.0-2, 1.2.0-1, 1.2.0-2~exp0

Timeline

  • Mar 20, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›