Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted SHA256 hash list. A crafted TPM event log could inject arbitrary SHA256 hashes into the verifier's trusted measurement database, enabling a remote attestation verifier to accept a compromised boot state. This issue affects go-attestation: through 0.6.0.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9r4w-jg96-92mv Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 24 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Jun 2026 09:45:00 +0000

Type Values Removed Values Added
Title Vendor Header Validation Failure Allows Trusted Hash Injection in TPM Event Logs

Wed, 24 Jun 2026 07:00:00 +0000

Type Values Removed Values Added
Title Vendor Header Validation Failure Allows Trusted Hash Injection in TPM Event Logs

Wed, 24 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google go-attestation
Vendors & Products Google
Google go-attestation

Wed, 24 Jun 2026 01:45:00 +0000

Type Values Removed Values Added
Description Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted SHA256 hash list. A crafted TPM event log could inject arbitrary SHA256 hashes into the verifier's trusted measurement database, enabling a remote attestation verifier to accept a compromised boot state. This issue affects go-attestation: through 0.6.0.
Weaknesses CWE-1285
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2026-06-24T12:57:35.436Z

Reserved: 2026-06-19T05:49:21.869Z

Link: CVE-2026-12681

cve-icon Vulnrichment

Updated: 2026-06-24T12:57:30.907Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-24T02:16:28.060

Modified: 2026-06-25T19:51:26.187

Link: CVE-2026-12681

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T09:30:06Z

Weaknesses