NA

CVE-2023-40549

Published: 29/01/2024 Updated: 25/04/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an malicious user to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat shim

redhat enterprise linux 8.0

redhat enterprise linux 9.0

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1061519 shim: CVE-2023-40546 CVE-2023-40547 CVE-2023-40548 CVE-2023-40549 CVE-2023-40550 CVE-2023-40551 Package: src:shim; Maintainer for src:shim is Debian EFI team <debian-efi@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 25 Jan 2024 20:57:01 UTC Sever ...
Description<!---->This CVE is under investigation by Red Hat Product Security ...