CVE-2022-21505

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Dec 24, 2024
Updated: Dec 27, 2024
CWE ID 346

Summary

CVE-2022-21505 is a vulnerability in the Linux kernel that allows for lockdown bypass when Integrity Measuring Architecture (IMA) appraisal is used with the "ima_appraise=log" boot parameter, even if Secure Boot is disabled or unavailable. IMA typically prevents this setting when Secure Boot is enabled, but it does not cover lockdown scenarios without Secure Boot. The impact of this vulnerability is significant as it poses a risk to confidentiality, integrity, and availability with a CVSS 3.1 Base Score of 6.7.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share