CVE-2026-82017
massBoot parameter injection flaw in IGEL OS 11 and 12 bypasses measured boot
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 store boot configuration in a registry area that is neither encrypted nor signed, yet is read and trusted by the device's signed bootloader. An attacker with physical access can write attacker-controlled Linux loader (kernel command-line) parameters into this area, and the signed bootloader will apply them on the next boot. The injected parameters execute with boot-environment privileges, and because the attack does not modify any measured boot code, TPM PCR measurements remain unchanged and measured-boot attestation will not flag the tampering. Any organization running unpatched IGEL OS 11 or 12 on thin clients or converted endpoints is affected, with exploitation requiring local physical access rather than network reachability. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates roughly a 0.2% chance of exploitation within 30 days.
What to do: Upgrade IGEL OS 12 devices to 12.7.6 or later and IGEL OS 11 devices to 11.11.150 or later. Until patched, prioritize restricting physical/console access on devices in publicly accessible or physically unsecured locations such as kiosks, lobbies and shared workspaces. Because this attack evades TPM measured-boot attestation, do not rely solely on PCR-based integrity checks to confirm boot integrity on unpatched devices.
| IGEL OS 12 | all 12.x versions before 12.7.6 |
| IGEL OS 11 | all 11.x versions before 11.11.150 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.
- Weakness
- CWE-345
- Vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.