{"id":"GHSA-9r4w-jg96-92mv","summary":"Go-Attestation: Hash injection into trusted measurement list via unskipped SignatureHeaderSize vendor bytes in parseEfiSignatureList()","details":"## Summary\n\n`parseEfiSignatureList()` in `attest/internal/events.go` does not skip\n`SignatureHeaderSize` vendor bytes before reading `EFI_SIGNATURE_LIST`\nsignature entries, violating UEFI specification section 31.4.1.\n\n## Impact\n\nFor `hashSHA256SigGUID` lists, attacker-controlled vendor header bytes are appended directly to the trusted SHA256 hash list. A crafted TPM event log can inject arbitrary SHA256 hashes into the verifier's trusted measurement database, allowing a remote attestation verifier to accept a compromised boot state as legitimate — breaking the core integrity guarantee of remote attestation.\n\n## Root Cause\n\nAfter `binary.Read(&signatures.Header)` reads 28 bytes, `buf` points to the start of the `SignatureHeaderSize` vendor bytes. Both entry loops start at `sigOffset := 0` instead of `sigOffset := SignatureHeaderSize`, causing vendor bytes to be read as signature entries.\n\n## Affected versions\n\nAll versions through commit `f877374` (2026-05-15).\n\n## Fix\n\nPull request: https://github.com/google/go-attestation/pull/502\n\n- Add bound check: `SignatureHeaderSize` must not exceed remaining list space\n- Skip `SignatureHeaderSize` bytes before both entry loops\n- Regression test: `TestParseEfiSignatureListNonZeroSignatureHeaderSize`","aliases":["CVE-2026-12681","GO-2026-5298"],"modified":"2026-09-12T05:15:04.755479683Z","published":"2026-06-12T15:04:43Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-12T15:04:43Z","nvd_published_at":"2026-06-24T02:16:28Z","cwe_ids":["CWE-1285","CWE-20"]},"references":[{"type":"WEB","url":"https://github.com/google/go-attestation/security/advisories/GHSA-9r4w-jg96-92mv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12681"},{"type":"WEB","url":"https://github.com/google/go-attestation/pull/502"},{"type":"WEB","url":"https://github.com/google/go-attestation/commit/b6e905e7ae52937f02b5ca494dd1c6a3ac7a1003"},{"type":"PACKAGE","url":"https://github.com/google/go-attestation"},{"type":"WEB","url":"https://github.com/google/go-attestation/releases/tag/v0.6.1"}],"affected":[{"package":{"name":"github.com/google/go-attestation","ecosystem":"Go","purl":"pkg:golang/github.com/google/go-attestation"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.6.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.6.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-9r4w-jg96-92mv/GHSA-9r4w-jg96-92mv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}