Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82017— IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area

Quick assessment

Affected
IGEL IGEL OS 12
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

IGEL OS 12 早于 12.7.6 以及 IGEL OS 11 早于 11.11.150 的版本存在一个启动注册表参数注入漏洞。拥有物理访问权限的攻击者可以通过向由签名启动加载器读取的未加密且未签名的配置区域写入数据,从而执行任意的 Linux 加载器参数。攻击者可以注入恶意的内核命令行参数,使这些参数以启动环境权限执行,且不会触发 TPM PCR 度量失败,因为该攻击并未修改受度量的启动代码。

CVSS 7.6 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82017

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area
Source: CVE Program / CVE List V5
Vulnerability Description
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
IGEL IGEL OS 12 12.0.0 ~ 12.7.6 -
IGEL IGEL OS 11 11.0.0 ~ 11.11.150 -

II. Public POCs for CVE-2026-82017

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82017

登录查看更多情报信息。

Vendor Advisories for CVE-2026-82017 (2)

Proof of Concept for CVE-2026-82017 (1)

Security Blog Posts for CVE-2026-82017 (1)

Other References for CVE-2026-82017 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-82017

No comments yet


Leave a comment