CVE-2026-82017: IGEL OS 12 / 11 Boot Registry Parameter Injection via Unsigned Configuration Area
IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IGEL OS 12to a version that resolves this vulnerability.Fixed in 12.7.6 - Upgrade
Upgrade
IGEL OS 11to a version that resolves this vulnerability.Fixed in 11.11.150
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Devices running IGEL OS 12 before 12.7.6 or IGEL OS 11 before 11.11.150 are affected when an attacker can obtain physical access to the device and write to its configuration area.
What does an attacker need to exploit it?
The attacker needs physical access and the ability to write to the unencrypted, unsigned configuration area. No prior privileges or user interaction are required according to the supplied severity vector.
Will TPM PCR measurements detect this attack?
No. The injected loader parameters do not modify the measured boot code, so the attack does not trigger TPM PCR measurement failures.
What is the impact of successful exploitation?
An attacker can inject malicious Linux kernel command-line parameters and execute them with boot-environment privileges, resulting in arbitrary code execution.