CVE-2025-47827
IGEL OS Use of a Key Past its Expiration Date Vulnerability
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.
MEDIUM · CVSS 4.6
⚠ CISA KEV
EPSS 0.00997
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- Public exploit or PoC is available
Sigma rules0
YARA rules0