CVE Vulnerabilities

CVE-2022-28735

Published: Jul 20, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The GRUB2s shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.

Affected Software

NameVendorStart VersionEnd Version
Grub2Gnu2.00 (including)2.06-3 (excluding)
Red Hat Enterprise Linux 8RedHatgrub2-1:2.02-123.el8_6.8*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatgrub2-1:2.02-87.el8_1.10*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatgrub2-1:2.02-87.el8_2.10*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatgrub2-1:2.02-99.el8_4.9*
Red Hat Enterprise Linux 9RedHatgrub2-1:2.06-27.el9_0.7*
Grub2Ubuntubionic*
Grub2Ubuntuimpish*
Grub2Ubuntuupstream*
Grub2-signedUbuntubionic*
Grub2-signedUbuntuesm-infra/bionic*
Grub2-signedUbuntuesm-infra/focal*
Grub2-signedUbuntuesm-infra/xenial*
Grub2-signedUbuntufocal*
Grub2-signedUbuntujammy*
Grub2-signedUbuntukinetic*
Grub2-signedUbuntutrusty*
Grub2-signedUbuntutrusty/esm*
Grub2-signedUbuntuxenial*
Grub2-unsignedUbuntubionic*
Grub2-unsignedUbuntuesm-infra/bionic*
Grub2-unsignedUbuntuesm-infra/focal*
Grub2-unsignedUbuntuesm-infra/xenial*
Grub2-unsignedUbuntufocal*
Grub2-unsignedUbuntujammy*
Grub2-unsignedUbuntukinetic*
Grub2-unsignedUbuntutrusty*
Grub2-unsignedUbuntuxenial*

References