PT-2026-83365 · Igel · Igel Os 11+1
CVSS v3.1
7.6
High
| Vector | AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IGEL OS 12 versions prior to 12.7.6
IGEL OS 11 versions prior to 11.11.150
Description
An issue exists where attackers with physical access can execute arbitrary Linux loader parameters. This is possible by writing to an unencrypted and unsigned configuration area that is read by the signed bootloader. This allows the injection of malicious kernel command line parameters that execute with boot environment privileges. Because the attack does not modify the measured boot code, it does not trigger TPM PCR measurement failures. TPM PCR (Trusted Platform Module Platform Configuration Register) measurements are used to ensure the integrity of the boot process.
Recommendations
Update IGEL OS 12 to version 12.7.6 or later.
Update IGEL OS 11 to version 11.11.150 or later.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Igel Os 11
Igel Os 12