Revision Date: | 2022-09-02 | Version: | 1 |
Title: | CVE-2022-2503 |
Description: |
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/firmware loads to just the trusted root filesystem. Device-mapper table reloads currently allow users with root privileges to switch out the target with an equivalent dm-linear target and bypass verification till reboot. This allows root to bypass LoadPin and can be used to load untrusted and unverified kernel modules and firmware, which implies arbitrary kernel execution and persistence for peripherals that do not verify firmware updates. We recommend upgrading past commit 4caae58406f8ceb741603eee460d79bacca9b1b5
|
Family: | unix | Class: | vulnerability |
Status: | | Reference(s): | Mitre CVE-2022-2503 SUSE CVE-2022-2503
|
Platform(s): | SUSE Linux Enterprise High Performance Computing 12 SP5 SUSE Linux Enterprise Server 12 SP5 SUSE Linux Enterprise Server for SAP Applications 12 SP4 SUSE Linux Enterprise Server for SAP Applications 12 SP5 SUSE Linux Enterprise Server for SAP Applications 15 SP2
| Product(s): | |
Definition Synopsis |
Release Information SUSE Linux Enterprise High Performance Computing 12 SP5 is installed
OR SUSE Linux Enterprise Server for SAP Applications 12 SP5 is installed
AND
kernel-default is affected
OR kernel-source is affected
OR kernel-source-azure is affected
OR Package Information
SUSE Linux Enterprise Server 12 SP5 is installed
AND
kernel-default is affected
OR kernel-default-base is affected
OR kernel-default-devel is affected
OR kernel-default-man is affected
OR kernel-devel is affected
OR kernel-macros is affected
OR kernel-source is affected
OR kernel-devel-azure is affected
OR kernel-source-azure is affected
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
AND Package Information
kernel-default is affected
OR kernel-default-devel is affected
OR reiserfs-kmp-default is affected
OR kernel-devel is affected
OR kernel-macros is affected
OR kernel-source is affected
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 12 SP4 is installed
AND Package Information
kernel-default is affected
OR kernel-default-base is affected
OR kernel-default-devel is affected
OR kernel-devel is affected
OR kernel-macros is affected
OR kernel-source is affected
|