---
id: CVE-2022-1665
title: >-
  A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM
  Power architecture can be booted by the grub in Secure Boot mode even though
  it shouldn't
summary: >-
  A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM
  Power architecture can be booted by the grub in Secure Boot mode even though
  it shouldn't. These kernel builds don't have the secure boot lockdown patches
  applie…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-1291
vendor: redhat
product: enterprise_linux
affected:
  - enterprise_linux = 8.0
published: '2022-06-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:43.947'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-1665'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2089529'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2089529'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00265
epssPercentile: 0.16893
ingestedAt: '2026-10-08T22:11:53.752Z'
---

## Overview

A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot validations, allowing the attacker to load another non-trusted code.

## Affected

- `enterprise_linux = 8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
