CVE-2015-7837

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:kernel-rt:7.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:37

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2015-2152.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2015-2152.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2015-2411.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2015-2411.html - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2015/10/15/6 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2015/10/15/6 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/77097 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/77097 - Third Party Advisory, VDB Entry
References () https://bugzilla.redhat.com/show_bug.cgi?id=1272472 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1272472 - Issue Tracking, Vendor Advisory
References () https://github.com/mjg59/linux/commit/4b2b64d5a6ebc84214755ebccd599baef7c1b798 - Issue Tracking, Third Party Advisory () https://github.com/mjg59/linux/commit/4b2b64d5a6ebc84214755ebccd599baef7c1b798 - Issue Tracking, Third Party Advisory

Information

Published : 2017-09-19 16:29

Updated : 2024-11-21 02:37


NVD link : CVE-2015-7837

Mitre link : CVE-2015-7837

CVE.ORG link : CVE-2015-7837


JSON object : View

Products Affected

redhat

  • enterprise_linux_workstation
  • enterprise_mrg
  • enterprise_linux_desktop
  • enterprise_linux
  • enterprise_linux_server_aus
  • kernel-rt
CWE
CWE-254

7PK - Security Features