GRUB Bootloader Misconfiguration in Fedora CoreOS
CVE-2022-3675
What is CVE-2022-3675?
In recent versions of Fedora CoreOS, a misconfiguration in the GRUB bootloader allows users to boot non-default OSTree deployments without requiring a password. This vulnerability allows individuals with access to the GRUB menu to revert the system to an earlier version, potentially negating crucial security fixes applied in the latest updates. It’s important to note that while the boot process can be bypassed without a password, a password is still necessary to modify kernel command-line arguments and access the GRUB command line.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CoreOS testing 36.20220906.2.0 and later
CoreOS next 36.20220906.1.0 and later
CoreOS stable 36.20220820.3.0 and later
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
