CVE-2022-21505: Medium severity Oracle Linux vulnerability
A bug that allows linux kernel lockdown to be trivially bypassed using IMA.
Other sources
An authentication bypass flaw was found in the Linux kernel’s IMA policy when a user performs lockdown. This flaw allows a local user to crash or potentially escalate their privileges on the system.
In the linux kernel, if IMA appraisal is used with the "imaappraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "imaappraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity, Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
— MITRE
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-21505?
CVE-2022-21505 is classified as a medium severity vulnerability.
How do I fix CVE-2022-21505?
To fix CVE-2022-21505, update the Linux kernel to version 5.14.0-284.11.1.el9_2 or later, or the appropriate patched version depending on your distribution.
What systems are affected by CVE-2022-21505?
CVE-2022-21505 affects specific versions of the Linux kernel, including 5.14.0-284.11.1.el9_2 and multiple versions of the Debian linux package.
What types of exploits are possible with CVE-2022-21505?
Exploitation of CVE-2022-21505 could lead to privilege escalation or system crashes for local users.
Is there a workaround for CVE-2022-21505?
There are no known workarounds for CVE-2022-21505; upgrading to a patched version is the recommended solution.