Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82018— IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File

Quick assessment

Affected
IGEL IGEL OS 12
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

IGEL OS 12 12.9.0 之前版本、12.8.3 LTS 以及 IGEL OS 11 11.11.150 之前版本中存在一个安全启动绕过漏洞,位于 GRUB 引导阶段。该漏洞允许物理接触设备的攻击者通过将名为 的未签名空文件放置到某个分区上,从而获得未经授权的 root 权限。 攻击者可利用 GRUB 在签名验证失败时采取“失败即开放”(fail-open)的特性,进入交互式 GRUB 命令行提示符,然后使用设备自身的内核并附加额外的命令行参数进行引导,从而在保持磁盘解锁状态且 TPM PCR 值未被修改

CVSS 6.1 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82018

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
IGEL OS 12 / 11 Secure Boot Bypass via Unsigned igel.conf File
Source: CVE Program / CVE List V5
Vulnerability Description
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
未能安全地进行程序失效(Failing Open)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
IGEL IGEL OS 12 12.0.0 ~ 12.8.2 -
IGEL IGEL OS 11 11.0.0 ~ 11.11.150 -

II. Public POCs for CVE-2026-82018

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82018

登录查看更多情报信息。

Vendor Advisories for CVE-2026-82018 (2)

Security Blog Posts for CVE-2026-82018 (1)

Other References for CVE-2026-82018 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-82018

No comments yet


Leave a comment