CVE-2022-2503: Linux Kernel LoadPin bypass via dm-verity table reload
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users with root privileges to switch out the target with an equivalent dm-linear target and bypass verification till reboot. This allows root to bypass LoadPin and can be used to load untrusted and unverified kernel modules and firmware, which implies arbitrary kernel execution and persistence for peripherals that do not verify firmware updates. We recommend upgrading past commit 4caae58406f8ceb741603eee460d79bacca9b1b5
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2503?
CVE-2022-2503 has a medium severity-level risk rating.
How do I fix CVE-2022-2503?
To fix CVE-2022-2503, ensure your Linux Kernel is updated to versions 5.19 or higher for Red Hat or appropriate patched versions for Debian.
What systems are affected by CVE-2022-2503?
CVE-2022-2503 affects various versions of the Linux Kernel across Red Hat and Debian distributions.
What is the impact of CVE-2022-2503 on system security?
CVE-2022-2503 may allow unauthorized module or firmware loading, potentially compromising the root filesystem's integrity.
Is there a public exploit for CVE-2022-2503?
As of now, there have been no widely reported public exploits for CVE-2022-2503.