Description
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.
Published: 2026-08-28
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 permit an attacker with physical access to write arbitrary kernel command line parameters to an unsigned, unencrypted configuration area. The unsigned data is read by the signed bootloader, allowing the injected parameters to run with boot‑level privileges without triggering TPM PCR measurement failures. Therefore, an attacker can execute arbitrary code during system startup with full system privileges.

Affected Systems

Affected systems include IGEL OS 11 versions before 11.11.150 and IGEL OS 12 versions before 12.7.6. The vulnerability is present in both the 11 and 12 product lines of IGEL OS.

Risk and Exploitability

According to the CVSS score of 8.6, this flaw is classified as high severity. EPSS data is not available, so the current exploitation probability is unclear, but the lack of KEV listing indicates no known mass exploitation yet. Exploitation requires physical access and the ability to write to the unsigned configuration cache. Attackers can use the provided script from the cited research or similar tooling to inject malicious parameters. The attack vector is physical and local, and the impact is achieved at boot time, before the operating system operational checks.

Generated by OpenCVE AI on August 28, 2026 at 23:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update that patches IGEL OS 12 to version 12.7.6 or later and IGEL OS 11 to 11.11.150 or later, as released by IGEL.
  • Limit physical access to the workstation by securing the device in a locked environment or restricting use of bootable media.
  • If an immediate patch is not possible, disable write access to the unsigned configuration area through the IGEL management console or lock the configuration filesystem to prevent unsigned changes.

Generated by OpenCVE AI on August 28, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.
Title IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-28T21:09:01.253Z

Reserved: 2026-08-27T21:39:20.459Z

Link: CVE-2026-82017

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T22:16:55.067

Modified: 2026-08-28T22:16:55.067

Link: CVE-2026-82017

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T00:00:15Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity