CVE-2026-82017: IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area

Published Aug 28, 2026
·
Updated

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.

Affected Software

2 affected components
IGEL IGEL OS 12<12.7.6
IGEL IGEL OS 11<11.11.150

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade IGEL OS 12 to a version that resolves this vulnerability.

    Fixed in 12.7.6
  2. Upgrade

    Upgrade IGEL OS 11 to a version that resolves this vulnerability.

    Fixed in 11.11.150

Event History

Aug 28, 2026
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Devices running IGEL OS 12 before 12.7.6 or IGEL OS 11 before 11.11.150 are affected when an attacker can obtain physical access to the device and write to its configuration area.

2

What does an attacker need to exploit it?

The attacker needs physical access and the ability to write to the unencrypted, unsigned configuration area. No prior privileges or user interaction are required according to the supplied severity vector.

3

Will TPM PCR measurements detect this attack?

No. The injected loader parameters do not modify the measured boot code, so the attack does not trigger TPM PCR measurement failures.

4

What is the impact of successful exploitation?

An attacker can inject malicious Linux kernel command-line parameters and execute them with boot-environment privileges, resulting in arbitrary code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203