CVE-2023-40549
29.01.2024, 17:15
An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | shim | 𝑥 < 15.8 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| secureboot-db |
| ||||||||||||||||||
| shim |
| ||||||||||||||||||
| shim-signed |
|
Common Weakness Enumeration
References