PT-2026-83366 · Igel · Igel Os
CVSS v3.1
6.1
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
IGEL OS 12 versions prior to 12.9.0
IGEL OS 12 version 12.8.3 LTS
IGEL OS 11 versions prior to 11.11.150
Description
A secure boot bypass exists in the GRUB boot stage. A physically present attacker can gain unauthorized root access by placing an unsigned empty file named
igel.conf on a partition. This exploits a fail-open signature verification behavior in GRUB, allowing the attacker to access an interactive GRUB prompt and boot the device kernel with additional command-line arguments. This process results in a root shell with the disk unlocked while TPM PCR (Platform Configuration Registers) values remain unaltered.Recommendations
Update IGEL OS 12 to version 12.9.0 or later.
Update IGEL OS 12 LTS to a version newer than 12.8.3.
Update IGEL OS 11 to version 11.11.150 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Igel Os