CVE-2023-40548
EUVD-2023-4511929.01.2024, 15:15
A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory corruption and can lead to a crash or data integrity issues during the boot phase.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | shim | 𝑥 < 15.8 |
| redhat | shim | 15.8:rc1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| secureboot-db |
| ||||||||||||||||||
| shim |
| ||||||||||||||||||
| shim-signed |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mokutil |
| ||||||||||||||||||||||||||
| shim-aa64 |
| ||||||||||||||||||||||||||
| shim-ia32 |
| ||||||||||||||||||||||||||
| shim-unsigned-ia32 |
| ||||||||||||||||||||||||||
| shim-unsigned-x64 |
| ||||||||||||||||||||||||||
| shim-x64 |
|
Azure Linux Releases
References