CVE-2022-28735
Summary
| CVE | CVE-2022-28735 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-20 01:15:00 UTC |
| Updated | 2023-08-25 23:15:00 UTC |
| Description | The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - [SECURITY PATCH 00/30] Multiple GRUB2 vulnerabilities - 2022/06/07 round | MISC | www.openwall.com | |
| July 2023 Grub Vulnerabilities in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| CVE - CVE-2022-28735 | MISC | cve.mitre.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159883 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-9471)
- 159884 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-9469)
- 159943 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-5099)
- 159967 Oracle Enterprise Linux Security Update for grub2, mokutil, shim, and shim-unsigned-x64 (ELSA-2022-5095)
- 159985 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-9596)
- 159986 Oracle Enterprise Linux Security Update for grub2 (ELSA-2022-9595)
- 161027 Oracle Enterprise Linux Security Update for grub2 (ELSA-2023-12952)
- 181042 Debian Security Update for grub2 (CVE-2022-28735)
- 240473 Red Hat Update for grub2, mokutil, shim, and shim-unsigned-x64 (RHSA-2022:5100)
- 240474 Red Hat Update for grub2, mokutil, shim, and shim-unsigned-x64 (RHSA-2022:5099)
- 240476 Red Hat Update for grub2, mokutil, shim, and shim-unsigned-x64 (RHSA-2022:5096)
- 240477 Red Hat Update for grub2, mokutil, shim, and shim-unsigned-x64 (RHSA-2022:5095)
- 282811 Fedora Security Update for grub2 (FEDORA-2022-27932fdd06)
- 282866 Fedora Security Update for grub2 (FEDORA-2022-9b4f9af4ce)
- 354332 Amazon Linux Security Advisory for grub2 : ALAS2022-2022-109
- 354535 Amazon Linux Security Advisory for grub2 : ALAS-2022-109
- 355137 Amazon Linux Security Advisory for grub2 : ALAS2023-2023-020
- 355617 Amazon Linux Security Advisory for grub2 : ALAS2-2023-2146
- 377130 Alibaba Cloud Linux Security Update for grub2, mokutil, shim, and shim-unsigned-x64 (ALINUX3-SA-2022:0134)
- 377622 Alibaba Cloud Linux Security Update for grub2, mokutil, shim, and shim-unsigned-x64 (ALINUX3-SA-2022:0164)
- 672021 EulerOS Security Update for grub2 (EulerOS-SA-2022-2242)
- 672031 EulerOS Security Update for grub2 (EulerOS-SA-2022-2255)
- 710619 Gentoo Linux GRUB Multiple Vulnerabilities (GLSA 202209-12)
- 752217 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2035-1)
- 752221 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2064-1)
- 752229 SUSE Enterprise Linux Security Update for grub2 (SUSE-SU-2022:2074-1)
- 907575 Common Base Linux Mariner (CBL-Mariner) Security Update for grub2 (27551-1)
- 940639 AlmaLinux Security Update for grub2, (ALSA-2022:5095)
- 940640 AlmaLinux Security Update for grub2, (ALSA-2022:5099)
- 960155 Rocky Linux Security Update for grub2, (RLSA-2022:5095)
- 960538 Rocky Linux Security Update for grub2, (RLSA-2022:5099)