5.5
CVSSv3

CVE-2023-40546

Published: 29/01/2024 Updated: 10/06/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it, leading to a crash under certain circumstances.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat shim

redhat enterprise linux 8.0

redhat enterprise linux 9.0

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1061519 shim: CVE-2023-40546 CVE-2023-40547 CVE-2023-40548 CVE-2023-40549 CVE-2023-40550 CVE-2023-40551 Package: src:shim; Maintainer for src:shim is Debian EFI team <debian-efi@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 25 Jan 2024 20:57:01 UTC Sever ...

Mailing Lists

githubcom/rhboot/shim/releases/tag/158 says it fixes these CVEs: CVE-2023-40546 mok: fix LogError() invocation CVE-2023-40547 - avoid incorrectly trusting HTTP headers CVE-2023-40548 Fix integer overflow on SBAT section size on 32-bit system CVE-2023-40549 Authenticode: verify that the signature header is in bounds CVE-2023-40 ...