Skip to content

kernel CVE-2022-21499

High
rpkelly published GHSA-6xgh-x8jw-5xg6 Jul 29, 2022

Package

kernel-5.10 (bottlerocket)

Affected versions

< 1.9.0

Patched versions

1.9.0
kernel-5.4 (bottlerocket)
< 1.9.0
1.9.0

Description

KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered.

Severity

High

CVE ID

CVE-2022-21499

Weaknesses

No CWEs