CVE-2023-43630: Config Partition Not Measured From 2 Fronts

Published Sep 20, 2023
·
Updated

Impact PCR14 is not included in the list of PCRs that seal/unseal the vault key. Additionally, the vault key uses SHA1 PCRs instead of SHA256. Thus an attacker with physical access can take out the disk, use a different computer to modify the files in the /config partition, and re-insert the disk and boot without the change being detected by measured boot and remote attestation.

Patches

Fixed in EVE version 9.4.3-lts

Workarounds

None (apart from preventing physical access to the device)

Resources

https://help.zededa.com/hc/en-us/articles/43295940828827-TPM-PCR-Index-Security-Implications https://github.com/lf-edge/eve/commit/d9383a7ee4e1c39f5c8c6d4a63cb2ebd00695e8a

Other sources

PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of the config partition not being measured correctly.

Also, the “vault” key is sealed/unsealed with SHA1 PCRs instead of SHA256. This issue was somewhat mitigated due to all of the PCR extend functions updating both the values of SHA256 and SHA1 for a given PCR ID.

However, due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, this is no longer the case for PCR14, as the code in “measurefs.go” explicitly updates only the SHA256 instance of PCR14, which means that even if PCR14 were to be added to the list of PCRs sealing/unsealing the “vault” key, changes to the config partition would still not be measured.

An attacker could modify the config partition without triggering the measured boot, this could result in the attacker gaining full control over the device with full access to the contents of the encrypted “vault”

MITRE

Affected Software

2 affected componentsFixes available
linuxfoundation Edge Virtualization Engine>=9.0.0<9.5.0
go/github.com/lf-edge/eve<0.0.0-20230126065759-d9383a7ee4e1
0.0.0-20230126065759-d9383a7ee4e1

Event History

Sep 20, 2023
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 4, 2026
Advisory Published
via GitHub·08:43 PM
Data Sourced
via GitHub·08:43 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-43630?

The severity of CVE-2023-43630 is high.

2

What software is affected by CVE-2023-43630?

The Linuxfoundation Edge Virtualization Engine versions between 9.0.0 and 9.5.0 are affected by CVE-2023-43630.

3

How can I fix CVE-2023-43630?

There is no known fix for CVE-2023-43630 at the moment. It is recommended to follow the guidance provided by the Linuxfoundation Edge Virtualization Engine or the security advisories.

4

What is the CWE of CVE-2023-43630?

The CWE of CVE-2023-43630 is 328, 522, 922.

5

Where can I find more information about CVE-2023-43630?

You can find more information about CVE-2023-43630 in the following reference: [link](https://asrg.io/security-advisories/config-partition-not-measured-from-2-fronts/)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203