CVE-2026-12681 | Google go-attestation up to 0.6.0 TPM parseEfiSignatureList improper validation of specified index, position, or offset in input (GHSA-9r4w-jg96-92mv)

SecurityVulns

A vulnerability was found in Google go-attestation up to 0.6.0. It has been declared as problematic. This affects the function parseEfiSignatureList of the component TPM Handler. Such manipulation leads to improper validation of specified index, position, or offset in input.

This vulnerability is documented as CVE-2026-12681. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More