CVE-2022-28735: High severity GNU GRUB2 vulnerability
A flaw was found in grub2. The shimlock verifier from grub2 allows non-kernel files to be loaded when secure boot is enabled, giving the possibility of unverified code or modules to be loaded when it should not be allowed.
Other sources
The GRUB2's shimlock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
The grub2's shimlock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in grub breaking the secure boot trust-chain.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-28735?
CVE-2022-28735 is a vulnerability in grub2 that allows non-kernel files to be loaded on shim-powered secure boot systems, breaking the secure boot trust-chain.
What is the severity of CVE-2022-28735?
The severity of CVE-2022-28735 is high with a severity rating of 7.8.
Which software versions are affected by CVE-2022-28735?
The affected software versions by CVE-2022-28735 include Red Hat grub2 versions 1:2.02-123.el8_6.8, 1:2.02-87.el8_1.10, 1:2.02-87.el8_2.10, 1:2.02-99.el8_4.9, and 1:2.06-27.el9_0.7, as well as Gnu Grub2 versions up to 2.06-3, Ubuntu grub2 version 2.06-3, and Debian grub2 versions 2.06-3~deb10u1, 2.06-3~deb10u3, 2.06-3~deb11u5, 2.06-3~deb11u4, 2.06-13, and 2.12~rc1-9.
How does CVE-2022-28735 affect systems?
CVE-2022-28735 allows unverified code and modules to be loaded in GRUB2 on shim-powered secure boot systems, compromising the secure boot trust-chain.
How can CVE-2022-28735 be fixed?
To fix CVE-2022-28735, it is recommended to update the affected software versions to the patched versions provided by the respective software vendors.