Exploit maturity not defined.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade SLES:15.6
grub2-arm64-efi
to version 2.12-150600.8.18.2 or higher.
Note: Versions mentioned in the description apply only to the upstream grub2-arm64-efi
package and not the grub2-arm64-efi
package as distributed by SLES
.
See How to fix?
for SLES:15.6
relevant fixed versions and status.
A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensitive information from the memory.