MEDIUM · 5.5

CVE-2015-7837

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot res...

Vulnerability Description

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.

CVSS Score

5.5

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
RedhatEnterprise Linux7.0
RedhatEnterprise Linux Desktop7.0
RedhatEnterprise Linux Server Aus7.3
RedhatEnterprise Linux Workstation7.0
RedhatEnterprise Mrg2.0
RedhatKernel-Rt7.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-7837?

CVE-2015-7837 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot res...

How severe is CVE-2015-7837?

CVE-2015-7837 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-7837?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server Aus, Redhat Enterprise Linux Workstation, Redhat Enterprise Mrg.