CVE-2015-7837

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:kernel-rt:7.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-09-19 16:29

Updated : 2024-02-04 19:29


NVD link : CVE-2015-7837

Mitre link : CVE-2015-7837

CVE.ORG link : CVE-2015-7837


JSON object : View

Products Affected

redhat

  • enterprise_linux_desktop
  • kernel-rt
  • enterprise_mrg
  • enterprise_linux
  • enterprise_linux_workstation
  • enterprise_linux_server_aus
CWE
CWE-254

7PK - Security Features