We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-28735



Description

The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.

Reserved 2022-04-05 | Published 2023-07-20 | Updated 2024-10-24 | Assigner canonical


MEDIUM: 6.7CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Product status

Any version before 2.06-3
affected

Credits

Julian Andres Klode finder

References

www.openwall.com/lists/oss-security/2022/06/07/5 mailing-list

cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28735 issue-tracking

security.netapp.com/advisory/ntap-20230825-0002/

cve.org (CVE-2022-28735)

nvd.nist.gov (CVE-2022-28735)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-28735

Support options

Helpdesk Chat, Email, Knowledgebase
Telegram Chat
Subscribe to our newsletter to learn more about our work.