PT-2026-51648 · Unknown · Go-Attestation

CVE-2026-12681

·

Published

2026-06-12

·

Updated

2026-06-25

CVSS v4.0

8.9

High

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions go-attestation versions prior to 0.6.1
Description Improper validation of a specified index, position, or offset in input occurs within the parseEfiSignatureList() function. The function fails to advance the buffer past vendor bytes before reading entries. In the case of hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted SHA256 hash list. Consequently, a crafted TPM (Trusted Platform Module) event log could inject arbitrary SHA256 hashes into the verifier's trusted measurement database, allowing a remote attestation verifier to accept a compromised boot state.
Recommendations Update go-attestation to version 0.6.1 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12681
GHSA-9R4W-JG96-92MV
GO-2026-5298

Affected Products

Go-Attestation