Shim: out-of-bounds read printing error messages
CVE-2023-40546
6.2MEDIUM
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 29 January 2024
What is CVE-2023-40546?
A notable flaw has been identified within Shim which arises during the creation of new ESL variables. When Shim encounters an error while creating a new variable, it attempts to log an error message. However, the parameters utilized by the logging function do not align correctly with the expected format string, which may lead to a system crash under specific conditions. This vulnerability poses a risk to various Red Hat products that rely on Shim for their secure boot functionality, potentially interrupting their operation and affecting overall system stability.
Affected Version(s)
Red Hat Enterprise Linux 7 0:15.8-3.el7
Red Hat Enterprise Linux 7 0:15.8-1.el7
Red Hat Enterprise Linux 8 0:15.8-4.el8_9