PT-2026-83365 · Igel · Igel Os 11+1

·

CVE-2026-82017

·

Published

2026-08-28

·

Updated

2026-08-29

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IGEL OS 12 versions prior to 12.7.6 IGEL OS 11 versions prior to 11.11.150
Description An issue exists where attackers with physical access can execute arbitrary Linux loader parameters. This is possible by writing to an unencrypted and unsigned configuration area that is read by the signed bootloader. This allows the injection of malicious kernel command line parameters that execute with boot environment privileges. Because the attack does not modify the measured boot code, it does not trigger TPM PCR measurement failures. TPM PCR (Trusted Platform Module Platform Configuration Register) measurements are used to ensure the integrity of the boot process.
Recommendations Update IGEL OS 12 to version 12.7.6 or later. Update IGEL OS 11 to version 11.11.150 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82017

Affected Products

Igel Os 11
Igel Os 12