Impact
The vulnerability in Debian live-boot allows an attacker to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is absent from the system. This flaw permits the system to boot without verifying the integrity of the root filesystem, effectively removing a foundational security guard that ensures the operating system has not been tampered with. The danger is that an attacker who can manipulate the boot environment may introduce or modify system binaries before the system becomes operational, thereby compromising confidentiality, integrity, and availability of the device.
Affected Systems
Affected product: Debian live-boot, commit ff8867c. No specific version range is listed in the advisory, but the vulnerability applies to builds containing this commit until the fix is applied. All Debian systems using live-boot that include this patch are at risk until updated.
Risk and Exploitability
The CVSS score of 4.1 places the vulnerability in the moderate range, indicating that it is not trivial but still significant. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation is currently documented. The likely attack vector is local or requires the attacker to have a foothold that permits removal or disabling of the .verity file on the boot media. As such, an attacker who can alter the boot components or grid the system with malicious scripts would be able to exploit this flaw. Given the medium severity and the local nature of the threat, system owners should treat this as an actionable risk until a patch is applied.
OpenCVE Enrichment