PT-2022-6553 · Linux+7 · Linux Kernel+7

Published

2022-05-31

·

Updated

2023-08-14

·

CVE-2022-2503

CVSS v3.1

6.9

Medium

VectorAV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the verity ctr() function in the drivers/md/dm-verity-target.c module of the Linux kernel's device-mapper subsystem. It allows an attacker with administrator privileges to bypass the LoadPin subsystem's restrictions and load untrusted kernel modules or firmware by switching out the target with an equivalent dm-linear target. This can lead to arbitrary kernel execution and persistence for peripherals that do not verify firmware updates.
Recommendations We recommend upgrading past commit 4caae58406f8ceb741603eee460d79bacca9b1b5 to resolve the issue. As a temporary workaround, consider restricting the use of the dm-verity target to minimize the risk of exploitation. Additionally, restrict access to the dm-linear target to prevent bypassing the LoadPin subsystem's verification.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2497
ALT-PU-2022-2523
ALT-PU-2022-2915
ALT-PU-2022-2919
ALT-PU-2023-1684
ALT-PU-2023-1741
ALT-PU-2023-1814
ALT-PU-2023-4894
AZL-10559
BDU:2023-02363
CESA-2022_7444
CESA-2022_7683
CVE-2022-2503
GHSA-6VQ3-W69P-W63M
OESA-2022-1880
OESA-2022-1881
OESA-2022-1893
OPENSUSE-SU-2022_3609-1
OPENSUSE-SU-2022_3693-1
OPENSUSE-SU-2022_3775-1
RHSA-2022:7444
RHSA-2022:7683
RHSA-2022:7933
RHSA-2022:8267
RHSA-2022_7444
RHSA-2022_7683
RHSA-2022_7933
RHSA-2022_8267
RHSA-2023:5627
SUSE-SU-2022:3584-1
SUSE-SU-2022:3586-1
SUSE-SU-2022:3587-1
SUSE-SU-2022:3599-1
SUSE-SU-2022:3609-1
SUSE-SU-2022:3688-1
SUSE-SU-2022:3693-1
SUSE-SU-2022:3704-1
SUSE-SU-2022:3775-1
SUSE-SU-2022:3779-1
SUSE-SU-2022:3809-1
SUSE-SU-2022:3810-1
USN-5594-1
USN-5599-1
USN-5602-1
USN-5616-1
USN-5622-1
USN-5623-1
USN-5630-1
USN-5639-1
USN-5647-1
USN-5654-1
USN-5660-1
USN-6001-1
USN-6013-1
USN-6014-1

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu