Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/lf-edge/eve
  4. ›
  5. GHSA-5jvg-8j6f-vpmc

GHSA-5jvg-8j6f-vpmc: Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts

September 20, 2023 (updated February 4, 2026)

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-phcg-h58r-gmcq. This link is maintained to preserve external references.

Original Description

PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of the config partition not being measured correctly.

Also, the “vault” key is sealed/unsealed with SHA1 PCRs instead of SHA256. This issue was somewhat mitigated due to all of the PCR extend functions updating both the values of SHA256 and SHA1 for a given PCR ID.

However, due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, this is no longer the case for PCR14, as the code in “measurefs.go” explicitly updates only the SHA256 instance of PCR14, which means that even if PCR14 were to be added to the list of PCRs sealing/unsealing the “vault” key, changes to the config partition would still not be measured.

An attacker could modify the config partition without triggering the measured boot, this could result in the attacker gaining full control over the device with full access to the contents of the encrypted “vault”

References

  • asrg.io/security-advisories/config-partition-not-measured-from-2-fronts
  • asrg.io/security-advisories/cve-2023-43630
  • github.com/advisories/GHSA-5jvg-8j6f-vpmc
  • nvd.nist.gov/vuln/detail/CVE-2023-43630

Code Behaviors & Features

Detect and mitigate GHSA-5jvg-8j6f-vpmc with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.0.0-20230126065759-d9383a7ee4e1

Fixed versions

  • 0.0.0-20230126065759-d9383a7ee4e1

Solution

Upgrade to version 0.0.0-20230126065759-d9383a7ee4e1 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-328: Use of Weak Hash
  • CWE-522: Insufficiently Protected Credentials

Source file

go/github.com/lf-edge/eve/GHSA-5jvg-8j6f-vpmc.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 05 Feb 2026 00:17:04 +0000.