Bug 2120701 (CVE-2022-34303) - CVE-2022-34303 shim: 3rd party shim allow secure boot bypass
Summary: CVE-2022-34303 shim: 3rd party shim allow secure boot bypass
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-34303
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1991048 2120703 2120706 2120707 2120708
Blocks: 2120649
TreeView+ depends on / blocked
 
Reported: 2022-08-23 15:02 UTC by Marco Benatto
Modified: 2023-05-09 16:35 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-05-09 16:35:05 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2023:2487 0 None None None 2023-05-09 07:52:49 UTC

Description Marco Benatto 2022-08-23 15:02:01 UTC
A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using external media.

Comment 1 Marco Benatto 2022-08-23 15:03:32 UTC
Created fwupd tracking bugs for this issue:

Affects: fedora-all [bug 2120703]

Comment 4 errata-xmlrpc 2023-05-09 07:52:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2023:2487 https://access.redhat.com/errata/RHSA-2023:2487

Comment 5 Product Security DevOps Team 2023-05-09 16:35:02 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-34303


Note You need to log in before you can comment on or make changes to this bug.