kernel CVE-2022-21499
Package
kernel-5.10
(bottlerocket)
Affected versions
< 1.9.0
Patched versions
1.9.0
kernel-5.4
(bottlerocket)
< 1.9.0
1.9.0
KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered.