We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-28735



Assignercanonical
Reserved2022-04-05
Published2023-07-20
Updated2024-10-24

Description

The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.



MEDIUM: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Product status

Any version before 2.06-3
affected

Credits

Julian Andres Klode finder

References

https://www.openwall.com/lists/oss-security/2022/06/07/5 mailing-list

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28735 issue-tracking

https://security.netapp.com/advisory/ntap-20230825-0002/

cve.org CVE-2022-28735

nvd.nist.gov CVE-2022-28735

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-28735
Subscribe to our newsletter to learn more about our work.