5.5
CVSSv3

CVE-2015-7837

Published: 19/09/2017 Updated: 15/07/2021
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secure_boot flag across kexec reboot.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat kernel-rt 7.0

redhat enterprise linux 7.0

redhat enterprise linux 7.2

redhat enterprise linux 7.3

redhat enterprise linux workstation 7.0

redhat enterprise linux desktop 7.0

redhat enterprise linux server aus 7.4

redhat enterprise linux server aus 7.3

redhat enterprise mrg 2.0

Vendor Advisories

Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix multiple security issues, address severalhundred bugs, and add numerous enhancements are now available as part ofthe ongoing support and maintenance of Red H ...
Synopsis Important: kernel-rt security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic Updated kernel-rt packages that fix multiple security issues, several bugs,and add various enhancements are now available for Red Hat EnterpriseLinux 7Red Hat Product Security has rated ...
Several security issues were fixed in the Linux kernel ...
A flaw was found in the way the Linux kernel handled the securelevel functionality after performing a kexec operation A local attacker could use this flaw to bypass the security mechanism of the securelevel/secureboot combination ...