ZeroHour

CVE-2026-82017

mass

Boot parameter injection flaw in IGEL OS 11 and 12 bypasses measured boot

CVSS 4.0
8.6 high
EPSS
<1%p5
Published
()
Modified
AI analysis

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 store boot configuration in a registry area that is neither encrypted nor signed, yet is read and trusted by the device's signed bootloader. An attacker with physical access can write attacker-controlled Linux loader (kernel command-line) parameters into this area, and the signed bootloader will apply them on the next boot. The injected parameters execute with boot-environment privileges, and because the attack does not modify any measured boot code, TPM PCR measurements remain unchanged and measured-boot attestation will not flag the tampering. Any organization running unpatched IGEL OS 11 or 12 on thin clients or converted endpoints is affected, with exploitation requiring local physical access rather than network reachability. No public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates roughly a 0.2% chance of exploitation within 30 days.

What to do: Upgrade IGEL OS 12 devices to 12.7.6 or later and IGEL OS 11 devices to 11.11.150 or later. Until patched, prioritize restricting physical/console access on devices in publicly accessible or physically unsecured locations such as kiosks, lobbies and shared workspaces. Because this attack evades TPM measured-boot attestation, do not rely solely on PCR-based integrity checks to confirm boot integrity on unpatched devices.

Affected
IGEL OS 12all 12.x versions before 12.7.6
IGEL OS 11all 11.x versions before 11.11.150
Estimated exposure
mass≈2–3 million endpoints (vendor-reported installed base of 2.5M+ IGEL OS devices; all unpatched 11.x/12.x deployments are in scope, though exploitation requires… — IGEL has publicly reported an installed base of more than 2.5 million endpoints, and the flaw is inherent to the boot configuration of all 11.x and 12.x releases prior to the fixed versions, so the unpatched population is plausibly in the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.

Weakness
CWE-345
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.