GHSA-5h7v-g49c-h887

Suggest an improvement
Source
https://github.com/advisories/GHSA-5h7v-g49c-h887
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-5h7v-g49c-h887/GHSA-5h7v-g49c-h887.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-5h7v-g49c-h887
Aliases
Published
2026-02-04T23:14:42Z
Modified
2026-02-19T20:56:26Z
Severity
  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
EVE Doesn't Protect Rootfs
Details

Impact

Measured boot validates BIOS, grub, kernel cmdline, and initrd but not the entire rootfs. Thus, an attacker can create an EVE-OS rootfs squashfs image with some files modified and take out the disk and replace the existing rootfs image without that being detected by measure boot and remote attestation.

Patches

Fixed in 8.6.0 and 8.12.1-lts

Workarounds

None

Database specific
{
    "cwe_ids":  [
        "CWE-345"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-04T23:14:42Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/lf-edge/eve/pkg/grub

Package

Name
github.com/lf-edge/eve/pkg/grub
View open source insights on deps.dev
Purl
pkg:golang/github.com/lf-edge/eve/pkg/grub

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20220708121648-5fef4d92e758

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-5h7v-g49c-h887/GHSA-5h7v-g49c-h887.json"