Description
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted SHA256 hash list. A crafted TPM event log could inject arbitrary SHA256 hashes into the verifier's trusted measurement database, enabling a remote attestation verifier to accept a compromised boot state. This issue affects go-attestation: through 0.6.0.
Published: 2026-06-24
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
Title Vendor Header Validation Failure Allows Trusted Hash Injection in TPM Event Logs

Wed, 24 Jun 2026 07:00:00 +0000

Type Values Removed Values Added
Title Vendor Header Validation Failure Allows Trusted Hash Injection in TPM Event Logs

Wed, 24 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google go-attestation
Vendors & Products Google
Google go-attestation

Wed, 24 Jun 2026 01:45:00 +0000

Type Values Removed Values Added
Description Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted SHA256 hash list. A crafted TPM event log could inject arbitrary SHA256 hashes into the verifier's trusted measurement database, enabling a remote attestation verifier to accept a compromised boot state. This issue affects go-attestation: through 0.6.0.
Weaknesses CWE-1285
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

Google Go-attestation
cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2026-06-24T12:57:35.436Z

Reserved: 2026-06-19T05:49:21.869Z

Link: CVE-2026-12681

cve-icon Vulnrichment

Updated: 2026-06-24T12:57:30.907Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T09:30:06Z

Weaknesses