Severity
Medium
Analysis Summary
CVE-2022-21505
Linux Kernel could allow a local authenticated attacker to bypass security restrictions, caused by a flaw when Secure Boot is disabled or unavailable. By sending a specially-crafted request to add ima_appraise=log to the kernel command line, an attacker could exploit this vulnerability to bypass the Lockdown protection feature.
Impact
- Security Bypass
Indicators Of Compromise
CVE
- CVE-2022-21505
Affected Vendors
Linux
Affected Products
- Linux Kernel
Remediation
Refer to Linux Kernel Website for patch, upgrade or suggested workaround information.