PT-2026-51648 · Unknown · Go-Attestation
CVE-2026-12681
·
Published
2026-06-12
·
Updated
2026-06-25
CVSS v4.0
8.9
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
go-attestation versions prior to 0.6.1
Description
Improper validation of a specified index, position, or offset in input occurs within the
parseEfiSignatureList() function. The function fails to advance the buffer past vendor bytes before reading entries. In the case of hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted SHA256 hash list. Consequently, a crafted TPM (Trusted Platform Module) event log could inject arbitrary SHA256 hashes into the verifier's trusted measurement database, allowing a remote attestation verifier to accept a compromised boot state.Recommendations
Update go-attestation to version 0.6.1 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Go-Attestation