← Voltar para CVEs
CVE-2021-3418
MEDIUM6.4
Descricao
If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and only affects grub2 versions prior to 2.06 and upstream and distributions using the shim_lock mechanism.
Detalhes CVE
Pontuacao CVSS v3.16.4
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeHIGH
Privilegios necessariosHIGH
Interacao do usuarioNONE
Publicado3/15/2021
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
gnu:grub2
Fraquezas (CWE)
CWE-281
Referencias
https://bugzilla.redhat.com/show_bug.cgi?id=1933757(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=1933757(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.