SCA: security update for github.com/lf-edge/eve/pkg/grub (GHSA-5h7v-g49c-h887)

high Tenable Self-Hosted Container Security Plugin ID 437557

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data
located in the vault. As per the “measured boot” design, the PCR values calculated at different stages of
the boot process will change if any of their respective parts are changed. This includes, among other
things, the configuration of the bios, grub, the kernel cmdline, initrd, and more. However, this mechanism
does not validate the entire rootfs, so an attacker can edit the filesystem and gain control over the
system. As the default filesystem used by EVE OS is squashfs, this is somewhat harder than an ext4, which
is easily changeable. This will not stop an attacker, as an attacker can repackage the squashfs with their
changes in it and replace the partition altogether. This can also be done directly on the device, as the
“003-storage-init” container contains the “mksquashfs” and “unsquashfs” binaries (with the corresponding
libs). An attacker can gain full control over the device without changing the PCR values, thus not
triggering the “measured boot” mechanism, and having full access to the vault. Note: This issue was
partially fixed in these commits (after disclosure to Zededa), where the config partition measurement was
added to PCR13: • aa3501d6c57206ced222c33aea15a9169d629141 • 5fef4d92e75838cc78010edaed5247dfbdae1889.
This issue was made viable in version 9.0.0 when the calculation was moved to PCR14 but it was not
included in the measured boot. (CVE-2023-43636)

See Also

https://github.com/advisories/GHSA-5h7v-g49c-h887

Plugin Details

Severity: High

ID: 437557

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 2/5/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.33

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-43636

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/4/2026

Vulnerability Publication Date: 9/20/2023

Reference Information

CVE: CVE-2023-43636

cwe: CWE-345