GHSA-3mq9-xhgq-r7gj

Suggest an improvement
Source
https://github.com/advisories/GHSA-3mq9-xhgq-r7gj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-3mq9-xhgq-r7gj/GHSA-3mq9-xhgq-r7gj.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-3mq9-xhgq-r7gj
Aliases
Published
2026-02-04T20:46:16Z
Modified
2026-02-05T03:56:25Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N CVSS Calculator
Summary
EVE: SSH as Root Unlockable Without Triggering Measured Boot
Details

Impact

On boot, the Pillar container checks for /config/authorized_keys. If present with a valid public key, it enables SSH on port 22 with root login. The /config partition is not protected by measured boot, is mutable and unencrypted.

This enables an attacker with physical access to the device to take out the disk, modify the /config partition using a separate server, then insert it, without the inserted key being flagged as an integrity voilation my measured boot and remote attestation.

Patches

Patched in 9.4.3-lts

Workarounds

None (apart from preventing physical access to the device)

Database specific
{
    "cwe_ids": [
        "CWE-522",
        "CWE-922"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-04T20:46:16Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/lf-edge/eve

Package

Name
github.com/lf-edge/eve
View open source insights on deps.dev
Purl
pkg:golang/github.com/lf-edge/eve

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20220708121648-5fef4d92e758

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-3mq9-xhgq-r7gj/GHSA-3mq9-xhgq-r7gj.json"