CVE-2022-28735

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/07/2023
Last modified:
25/08/2023

Description

The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:grub2:*:*:*:*:*:*:*:* 2.00 (including) 2.06-3 (excluding)