Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-28735
HistoryJul 20, 2023 - 1:15 a.m.

Code injection

2023-07-2001:15:00
PRIOn knowledge base
www.prio-n.com
10
grub2
shim_lock verifier
non-kernel files
secure boot
trust-chain

8.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

The GRUB2’s shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.

CPENameOperatorVersion
grub2ge2.00
grub2lt2.06