PT-2025-23933 · Igel +1 · Igel Os +1

Zedeldi

·

Published

2025-05-29

·

Updated

2025-11-25

·

CVE-2025-47827

CVSS v2.0
4.9
VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions IGEL OS versions prior to 11
Description IGEL OS versions prior to 11 contain a flaw in the
igel-flash-driver
module that improperly verifies cryptographic signatures during the Secure Boot process. This allows a crafted root filesystem to be mounted from an unverified SquashFS image, potentially enabling the loading of untrusted kernels and rootkits. The issue stems from a bypass of Secure Boot protections, potentially exploitable with minimal physical access. Multiple reports indicate the availability of a proof-of-concept (PoC) exploit. The vulnerability affects Linux systems relying on Microsoft’s 3rd Party UEFI CA certificate.
Recommendations Update IGEL OS to version 11 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

BDU:2025-12993
CVE-2025-47827

Affected Products

Igel Os
Windows