CVE-2022-21505

MEDIUM

Oracle Linux - Lockdown Bypass via IMA Appraisal Log Mode

Title source: llm
STIX 2.1

Description

In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity, Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://linux.oracle.com/cve/CVE-2022-21505.html

Scores

CVSS v3 6.7
EPSS 0.0007
EPSS Percentile 21.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-346
Status published
Products (3)
oracle/linux 7
oracle/linux 8
oracle/linux 9
Published Dec 24, 2024
Tracked Since Feb 18, 2026