Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w739-fjv8-98pq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

EPSS

Процентиль: 5%
0.00024
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.4
ubuntu
почти 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
redhat
почти 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
nvd
почти 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

CVSS3: 6.4
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 6.4
debian
почти 5 лет назад

GRUB2 fails to validate kernel signature when booted directly without ...

EPSS

Процентиль: 5%
0.00024
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-347