Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31092
HistoryJun 30, 2021 - 12:18 p.m.

Protection Bypass

2021-06-3012:18:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22

0.001 Low

EPSS

Percentile

20.4%

The Linux kernel is vulnerable to Protection Bypass. It does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c. A flaw was found in the Linux kernel in certs/blacklist.c, When signature entries for EFI_CERT_X509_GUID are contained in the Secure Boot Forbidden Signature Database, the entries are skipped. This can cause a security threat and breach system integrity, confidentiality and even lead to a denial of service problem.