RHSA-2024:1835HighCVSS 8.3
Red Hat Security Advisory: shim security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2023-40546 — shim: Out-of-bounds read printing error messages CVE-2023-40547 — shim: RCE in http boot support may lead to Secure Boot bypass CVE-2023-40548 — shim: Interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems CVE-2023-40549 — shim: Out-of-bounds read in verify_buffer_authenticode() malformed PE file CVE-2023-40550 — shim: Out-of-bound read in verify_buffer_sbat() CVE-2023-40551 — shim: out of bounds read when parsing MZ binaries
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2024:1835
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2234589
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241782
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241796
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2241797
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259915
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2259918
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1835.json