CVE-2023-40546
29.01.2024, 17:15
A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it, leading to a crash under certain circumstances.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | shim | 𝑥 < 15.8 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| secureboot-db |
| ||||||||||||||||||
| shim |
| ||||||||||||||||||
| shim-signed |
|
Common Weakness Enumeration
References