Authentication Bypass by Primary Weakness Affecting kernel package, versions <0:5.15.72-43.134.amzn2022


Severity

Recommended
high

Based on Amazon Linux security rating.

Threat Intelligence

EPSS
0.04% (12th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-AMZN2022-KERNEL-3043504
  • published14 Oct 2022
  • disclosed24 Dec 2024

Introduced: 14 Oct 2022

CVE-2022-21505  (opens in a new tab)
CWE-305  (opens in a new tab)

How to fix?

Upgrade Amazon-Linux:2022 kernel to version 0:5.15.72-43.134.amzn2022 or higher.
This issue was patched in ALAS2022-2022-150.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel package and not the kernel package as distributed by Amazon-Linux. See How to fix? for Amazon-Linux:2022 relevant fixed versions and status.

In the linux kernel, if IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine when Secure Boot is disabled or unavailable. IMA prevents setting "ima_appraise=log" from the boot param when Secure Boot is enabled, but this does not cover cases where lockdown is used without Secure Boot. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity, Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS Scores

version 3.1