A vulnerability in the Linux kernel that allows bypassing Lockdown mode restrictions.

A vulnerability (CVE-2022-21505) has been discovered in the Linux kernel, allowing an easy bypass of the Lockdown protection mechanism, which restricts root user access to the kernel and blocks methods for circumventing UEFI Secure Boot. The proposed bypass uses the IMA (Integrity Measurement Architecture) kernel subsystem, which is designed to verify the integrity of operating system components through digital signatures and hashes.

In lockdown mode, access to /dev/mem, /dev/kmem, /dev/port, /proc/kcore, debugfs, the kprobes debugging mode, mmiotrace, tracefs, BPF, PCMCIA CIS (Card Information Structure), certain ACPI interfaces, and CPU MSR registers is restricted. Calls to kexec_file and kexec_load are blocked, sleep mode is prohibited, DMA usage for PCI devices is limited, ACPI code import from EFI variables is disallowed, and input/output port manipulations, including changing the interrupt number and input/output port for the serial port, are not allowed.

The essence of the vulnerability is that, when using the boot parameter 'ima_appraise=log', a call to kexec is permitted to load a new copy of the kernel if the Secure Boot mode is not active and Lockdown is used independently of it. IMA prevents the enabling of 'ima_appraise' when Secure Boot is active, but does not take into account the potential for Lockdown to be used separately from Secure Boot.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster