VDB
Sign up
HIGH

GHSA-6w5f-5wgr-qjg5

Constellation allows Emergency shell access during initramfs boot phase

Quick fix

GHSA-6w5f-5wgr-qjg5 — github.com/edgelesssys/constellation/v2: upgrade to the fixed version with the command below.

go get github.com/edgelesssys/constellation/v2@v2.6.0

Details

### Impact

An active attacker could let the boot fail on purpose in the initramfs, dropping the serial console into an emergency shell. This gives attackers with access to the serial console full control over the VM.

### Patches

The issue has been patched in [v2.6.0](https://github.com/edgelesssys/constellation/releases/tag/v2.6.0).

### Workarounds

none

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/edgelesssys/constellation/v2
Introduced in: 0Fixed in: 2.6.0
Fixgo get github.com/edgelesssys/constellation/v2@v2.6.0

References