CVE-2022-1665CWE-1291

A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it…

published June 21, 2022

CVSS
EPSS
0%
Percentile
18.2
In the wild
Unconfirmed
What it is

A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.

The record
Technical detail
CVSS
Not scored
CVSS v4.0
Not supplied
EPSS
0.00265 · 18.2th percentile
Weakness
CWE-1291 · Public Key Re-Use for Signing both Debug and Production Code
Published
2022-06-21T14:23Z
EPSS history
Timeline
  • 21 JUN 14:23Z
    A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it…
    cvelistv5