Impact
The vault key is sealed using SHA1 PCRs instead of SHA256 PCRs
Thus an attacker with physical access to an EVE-OS device can try to brute force creating a kernel or rootfs image which produces the same SHA1 PCR but with malicious content.
Patches
Fixed in 9.4.3-lts and 10.1.0
Workarounds
None
References
Impact
The vault key is sealed using SHA1 PCRs instead of SHA256 PCRs
Thus an attacker with physical access to an EVE-OS device can try to brute force creating a kernel or rootfs image which produces the same SHA1 PCR but with malicious content.
Patches
Fixed in 9.4.3-lts and 10.1.0
Workarounds
None
References