EVE: SSH as Root Unlockable Without Triggering Measured Boot
Package
Affected versions
< 0.0.0-20220708121648-5fef4d92e758
Patched versions
0.0.0-20220708121648-5fef4d92e758
Description
Published to the GitHub Advisory Database
Feb 4, 2026
Reviewed
Feb 4, 2026
Last updated
Feb 4, 2026
Impact
On boot, the Pillar container checks for /config/authorized_keys. If present with a valid public key, it enables SSH on port 22 with root login. The /config partition is not protected by measured boot, is mutable and unencrypted.
This enables an attacker with physical access to the device to take out the disk, modify the /config partition using a separate server, then insert it, without the inserted key being flagged as an integrity voilation my measured boot and remote attestation.
Patches
Patched in 9.4.3-lts
Workarounds
None (apart from preventing physical access to the device)
References