A systemd 262 and dracut integration gap can preserve the PCR state meant to block TPM-bound LUKS key release after an attacker-controlled root boots.
Affects
Linux systems using systemd 262, a Dracut-generated initramfs, TPM2-backed LUKS auto-unlock, and a policy that relies on PCR15 changing from zero before leaving the initramfs.
systemd 262 moved volume-key measurement to systemd-pcrextend.socket. Affected dracut initrds omit that socket; cryptsetup warns but continues, so PCR 15 can remain zero through leave-initrd.
Detail and 6 sources
With device custody, an attacker can retain the signed UKI while substituting the root filesystem. A proposed dracut change restores the socket, but affected pre-fix images remain accepted and revocation status is unresolved.
Chain to watch
Attacker obtains the powered-off device and substitutes an attacker-controlled root filesystem while retaining the target's signed UKI→↓Secure Boot and the configured PCR 7 policy still admit the signed boot chain→↓systemd-cryptsetup attempts to measure the unlocked volume key through systemd-pcrextend.socket→↓The dracut-generated initrd lacks that socket, so measurement fails with a warning while boot continues→↓PCR 15 remains at the enrolled zero value through the transition to the attacker-controlled root→↓The TPM policy can still authorize release of the sealed LUKS key after the trust boundary has been crossed→↓The missing PCR extension is demonstrated, but public evidence does not show the TPM releasing and the attacker using the original disk’s LUKS key from the substituted root.
Unverified chainReproduce systemd 262 with dracut 111 or 112, boot its signed UKI against a controlled alternate root, and test whether the TPM releases a usable key for the original LUKS volume after leave-initrd.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.