Executive brief
Google's go-attestation library, which is used to verify the integrity of a computer's boot process using TPM hardware, contains a flaw in how it processes UEFI signature lists. An attacker can provide a specially crafted boot log that injects unauthorized security hashes into the system's trusted database. This could allow a compromised or malicious operating system to be falsely identified as secure and legitimate by remote monitoring services.
Technical details
The vulnerability exists in the `parseEfiSignatureList()` function within `attest/internal/events.go`. The function fails to advance the buffer pointer past the `SignatureHeaderSize` vendor-specific bytes (as defined in UEFI spec 31.4.1) before reading signature entries. Consequently, for `hashSHA256SigGUID` lists, attacker-controlled vendor header bytes are incorrectly interpreted and appended to the trusted SHA256 hash list. A remote attacker can exploit this by providing a malicious TPM event log, leading to a bypass of remote attestation integrity checks. The issue is fixed in version 0.6.1 by implementing proper bounds checking and skipping the vendor header bytes.
Affected products
- Google go-attestation <= 0.6.0
Timeline
- 2026-05-15: other: Last affected commit identified
- 2026-05-21: advisory: GitHub Security Advisory published
- 2026-06-19: patched: Version 0.6.1 released
- 2026-06-24: disclosed: NVD publication date