EVE Doesn't Protect Rootfs
Package
Affected versions
< 0.0.0-20220708121648-5fef4d92e758
Patched versions
0.0.0-20220708121648-5fef4d92e758
Description
Published to the GitHub Advisory Database
Feb 4, 2026
Reviewed
Feb 4, 2026
Last updated
Feb 4, 2026
Impact
Measured boot validates BIOS, grub, kernel cmdline, and initrd but not the entire rootfs. Thus, an attacker can create an EVE-OS rootfs squashfs image with some files modified and take out the disk and replace the existing rootfs image without that being detected by measure boot and remote attestation.
Patches
Fixed in 8.6.0 and 8.12.1-lts
Workarounds
None
References