CVE-2022-28735
published 2023-07-20CVE-2022-28735: The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.32%
23.6th percentile
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.06-3 (bookworm) | grub2 2.06-3 (bookworm) |
| gnu | grub2 | >= 0 < 2.06-3~deb11u1 | 2.06-3~deb11u1 |
| gnu | grub2 | >= 0 < 2.06-3 | 2.06-3 |
| gnu | grub2 | >= 0 < 2.06-3 | 2.06-3 |
| gnu | grub2 | >= 0 < 2.06-3 | 2.06-3 |
| gnu | grub2 | >= 2.00 < 2.06-3 | 2.06-3 |
| gnu_project | gnu_grub | < 2.06-3 | 2.06-3 |
| msrc | azl3_grub2_2.06-14_on_azure_linux_3.0 | — | — |
| msrc | azl3_grub2_2.06-23_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | shim | >= 0 < 15.7-0ubuntu1 | 15.7-0ubuntu1 |
| redhat | shim | >= 0 < 15.7-0ubuntu1 | 15.7-0ubuntu1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_msrc7.8HIGH
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
vendor_ubuntu4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
osv·2023-09-08·CVSS 4.5
CVE-2021-3695 [MEDIUM] grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
Daniel Axtens discovered that specially crafted images could cause a
heap-based out-of-bonds write. A local attacker could possibly use
this to circumvent secure boot protections. (CVE-2021-3695)
Daniel Axtens discovered that specially crafted images could cause
out-of-bonds read and write. A local attacker could possibly use this
to circumvent secure boot protections. (CVE-2021-3696)
Daniel Axtens discovered that specially crafted images could cause
buffer underwrite which allows arbitrary data to be written to a heap.
A local attacker could possibly use this to circumvent secure
boot protections. (CVE-2021-3697)
It was discovered that GRUB2 configuration files were created with
the wrong permissions. An attacker could
GHSA
GHSA-w8wh-9mrg-3ff5: The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems
ghsa_unreviewed·2023-07-20
CVE-2022-28735 [HIGH] GHSA-w8wh-9mrg-3ff5: The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
OSV
CVE-2022-28735: The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems
osv·2023-07-20·CVSS 7.8
CVE-2022-28735 [HIGH] CVE-2022-28735: The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
Ubuntu
GRUB2 vulnerabilities
vendor_ubuntu·2023-09-08·CVSS 4.5
CVE-2022-28737 [MEDIUM] GRUB2 vulnerabilities
Title: GRUB2 vulnerabilities
Summary: Several security issues were fixed in GRUB2.
Daniel Axtens discovered that specially crafted images could cause a
heap-based out-of-bonds write. A local attacker could possibly use
this to circumvent secure boot protections. (CVE-2021-3695)
Daniel Axtens discovered that specially crafted images could cause
out-of-bonds read and write. A local attacker could possibly use this
to circumvent secure boot protections. (CVE-2021-3696)
Daniel Axtens discovered that specially crafted images could cause
buffer underwrite which allows arbitrary data to be written to a heap.
A local attacker could possibly use this to circumvent secure
boot protections. (CVE-2021-3697)
It was discovered that GRUB2 configuration files were created with
the wrong permissions.
Microsoft
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2
vendor_msrc·2023-07-11·CVSS 7.8
CVE-2022-28735 [MEDIUM] The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional produ
Red Hat
grub2: shim_lock verifier allows non-kernel files to be loaded
vendor_redhat·2022-06-07·CVSS 6.7
CVE-2022-28735 [MEDIUM] CWE-829 grub2: shim_lock verifier allows non-kernel files to be loaded
grub2: shim_lock verifier allows non-kernel files to be loaded
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
A flaw was found in grub2. The shim_lock verifier from grub2 allows non-kernel files to be loaded when secure boot is enabled, giving the possibility of unverified code or modules to be loaded when it should not be allowed.
Package: grub2 (Red Hat Enterprise Linux 7) - Out of support scope
Debian
CVE-2022-28735: grub2 - The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powe...
vendor_debian·2022·CVSS 6.7
CVE-2022-28735 [MEDIUM] CVE-2022-28735: grub2 - The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powe...
The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain.
Scope: local
bookworm: resolved (fixed in 2.06-3)
bullseye: resolved (fixed in 2.06-3~deb11u1)
forky: resolved (fixed in 2.06-3)
sid: resolved (fixed in 2.06-3)
trixie: resolved (fixed in 2.06-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28735https://security.netapp.com/advisory/ntap-20230825-0002/https://www.openwall.com/lists/oss-security/2022/06/07/5https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28735https://security.netapp.com/advisory/ntap-20230825-0002/https://www.openwall.com/lists/oss-security/2022/06/07/5
2023-07-20
Published