OSV 1.4.0 · unreviewed · 修改于 2026-08-29 08:31
发布时间
2026-08-29 08:31
GitHub 审查时间
—
NVD 发布时间
2026-08-29 06:16
源文件
advisories/unreviewed/2026/08/GHSA-7c38-49cx-fjvw/GHSA-7c38-49cx-fjvw.json
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.
该公告没有提供结构化的受影响软件包信息。