PT-2022-14033 · Red Hat · Red Hat
Marco Benatto
·
Published
2022-06-21
·
Updated
2022-08-18
·
CVE-2022-1665
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Linux for IBM Power architecture (affected versions not specified)
Description
A set of pre-production kernel packages can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied, allowing an attacker to bypass secure boot validations and load non-trusted code.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat