Description
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
Published: 2023-07-20
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-33174 The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
Ubuntu USN Ubuntu USN USN-6355-1 GRUB2 vulnerabilities
History

Thu, 24 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Gnu Grub2
Redhat Enterprise Linux Rhel E4s Rhel Eus
cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2025-02-13T16:32:36.760Z

Reserved: 2022-04-05T21:59:08.760Z

Link: CVE-2022-28735

cve-icon Vulnrichment

Updated: 2024-08-03T06:03:52.586Z

cve-icon NVD

Status : Modified

Published: 2023-07-20T01:15:10.320

Modified: 2024-11-21T06:57:49.953

Link: CVE-2022-28735

cve-icon Redhat

Severity : Moderate

Publid Date: 2022-06-07T17:00:00Z

Links: CVE-2022-28735 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses