CVE-2023-43636: EVE Doesn't Protect Rootfs
Measured boot validates BIOS, grub, kernel cmdline, and initrd but not the entire rootfs. Thus, an attacker can create an EVE-OS rootfs squashfs image with some files modified and take out the disk and replace the existing rootfs image without that being detected by measure boot and remote attestation.
References
- asrg.io/security-advisories/19274
- asrg.io/security-advisories/cve-2023-43636
- github.com/advisories/GHSA-5h7v-g49c-h887
- github.com/lf-edge/eve
- github.com/lf-edge/eve/commit/5fef4d92e75838cc78010edaed5247dfbdae1889
- github.com/lf-edge/eve/commit/aa3501d6c57206ced222c33aea15a9169d629141
- github.com/lf-edge/eve/security/advisories/GHSA-5h7v-g49c-h887
- nvd.nist.gov/vuln/detail/CVE-2023-43636
Code Behaviors & Features
Detect and mitigate CVE-2023-43636 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →