PT-2026-6369 · Go · Github.Com/Lf-Edge/Eve/Pkg/Grub

Published

2026-02-04

·

Updated

2026-02-04

CVSS v3.1

6.7

Medium

VectorAV:P/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Impact

Measured boot validates BIOS, grub, kernel cmdline, and initrd but not the entire rootfs. Thus, an attacker can create an EVE-OS rootfs squashfs image with some files modified and take out the disk and replace the existing rootfs image without that being detected by measure boot and remote attestation.

Patches

Fixed in 8.6.0 and 8.12.1-lts

Workarounds

None

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

GHSA-5H7V-G49C-H887

Affected Products

Github.Com/Lf-Edge/Eve/Pkg/Grub