PT-2022-14033 · Red Hat · Red Hat

Marco Benatto

·

Published

2022-06-21

·

Updated

2022-08-18

·

CVE-2022-1665

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux for IBM Power architecture (affected versions not specified)
Description A set of pre-production kernel packages can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied, allowing an attacker to bypass secure boot validations and load non-trusted code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2022-1665

Affected Products

Red Hat