Shim: out-of-bound read in verify_buffer_sbat()
CVE-2023-40550
5.5MEDIUM
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 29 January 2024
Summary
An out-of-bounds read flaw has been identified within the Shim component, specifically during the validation of SBAT information. This vulnerability may allow for the unintentional exposure of sensitive data during the system’s boot phase. Organizations using Red Hat products with Shim should apply the latest security patches to mitigate the risks associated with this vulnerability, ensuring that their systems retain data integrity and security.
Affected Version(s)
Red Hat Enterprise Linux 7 0:15.8-3.el7
Red Hat Enterprise Linux 7 0:15.8-1.el7
Red Hat Enterprise Linux 8 0:15.8-4.el8_9
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database