← All Advisories

CVE-2026-82017

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-82017

Key Details

CVECVE-2026-82017
CVSS Score / Version7.6 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is physical; attack complexity is low; privileges required is none; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsIGEL IGEL OS 12 and IGEL IGEL OS 11
Classified asCWE-345 (Insufficient Verification of Data Authenticity)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
IGELIGEL OS 12
IGELIGEL OS 11
SubsystemsGeneral OT
SectorsMultiple

What to Know

IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the signed bootloader. Attackers can inject malicious kernel command line parameters that execute with boot environment privileges without triggering TPM PCR measurement failures, as the attack does not modify the measured boot code. (NVD)

What to Do

Monitor IGEL's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-82017
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-82017