CVE-2022-21505
Last modified
CVE-2022-21505 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity, Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Linux | 7 |
| Oracle | Linux | 8 |
| Oracle | Linux | 9 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-21505?
How severe is CVE-2022-21505?
How do I fix CVE-2022-21505?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-21497Vulnerability in the Oracle Web Services Manager product of …8.1
- CVE-2022-21498Vulnerability in the Java VM component of Oracle Database Se…6.5
- CVE-2022-21499KGDB and KDB allow read and write access to kernel memory, a…6.7
- CVE-2022-21500Vulnerability in Oracle E-Business Suite (component: Manage …7.5
- CVE-2022-21503Vulnerability in the Oracle Cloud Infrastructure product of …4.9
- CVE-2022-21504The code in UEK6 U3 was missing an appropiate file descripto…5.5
- CVE-2022-21508Vulnerability in Oracle Essbase (component: Security and Pro…5.8
- CVE-2022-21509Vulnerability in the MySQL Server product of Oracle MySQL (c…5.5
- CVE-2022-2151The Best Contact Management Software WordPress plugin throug…4.8
- CVE-2022-21510Vulnerability in the Oracle Database - Enterprise Edition Sh…8.8
- CVE-2022-21511Vulnerability in the Oracle Database - Enterprise Edition Re…7.2
- CVE-2022-21512Vulnerability in the PeopleSoft Enterprise PeopleTools produ…4.4
Are you affected by CVE-2022-21505?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
