Vulnerability Description
A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2089529Issue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2089529Issue TrackingVendor Advisory
FAQ
What is CVE-2022-1665?
CVE-2022-1665 is a vulnerability with a CVSS score of 8.2 (HIGH). A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have th...
How severe is CVE-2022-1665?
CVE-2022-1665 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1665?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux.