CVE-2015-7837

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.

References

https://github.com/mjg59/linux/commit/4b2b64d5a6ebc84214755ebccd599baef7c1b798

https://bugzilla.redhat.com/show_bug.cgi?id=1272472

http://www.openwall.com/lists/oss-security/2015/10/15/6

http://rhn.redhat.com/errata/RHSA-2015-2411.html

http://rhn.redhat.com/errata/RHSA-2015-2152.html

http://www.securityfocus.com/bid/77097

Details

Source: MITRE

Published: 2017-09-19

Updated: 2017-10-05

Type: CWE-254

Risk Information

CVSS v2

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (13 total)

IDNameProductFamilySeverity
147512EulerOS Virtualization 2.9.1 : kernel (EulerOS-SA-2021-1604)NessusHuawei Local Security Checks
high
144731EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2021-1039)NessusHuawei Local Security Checks
high
142148EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-2311)NessusHuawei Local Security Checks
high
120977Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2019-4316)NessusOracle Linux Local Security Checks
high
102819Ubuntu 14.04 LTS : linux-lts-xenial vulnerabilities (USN-3405-2)NessusUbuntu Local Security Checks
high
102818Ubuntu 16.04 LTS : linux, linux-aws, linux-gke, linux-raspi2, linux-snapdragon vulnerabilities (USN-3405-1)NessusUbuntu Local Security Checks
high
93679OracleVM 3.4 : Unbreakable / etc (OVMSA-2016-0100)NessusOracleVM Local Security Checks
critical
93148Oracle Linux 6 / 7 : Unbreakable Enterprise kernel (ELSA-2016-3596)NessusOracle Linux Local Security Checks
critical
88571RHEL 7 : kernel-rt (RHSA-2015:2411)NessusRed Hat Local Security Checks
medium
87559Scientific Linux Security Update : kernel on SL7.x x86_64 (20151119)NessusScientific Linux Local Security Checks
medium
87135CentOS 7 : kernel (CESA-2015:2152)NessusCentOS Local Security Checks
high
87090Oracle Linux 7 : kernel (ELSA-2015-2152)NessusOracle Linux Local Security Checks
high
86972RHEL 7 : kernel (RHSA-2015:2152)NessusRed Hat Local Security Checks
high