Shim: out of bounds read when parsing mz binaries
CVE-2023-40551
5.1MEDIUM
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 29 January 2024
Summary
An identified flaw in the MZ binary format used within Shim has the potential to enable an out-of-bounds read condition. This issue could result in system crashes or, more critically, the unintended exposure of sensitive data during the boot phase of the operating system. Proper mitigation strategies are essential to ensure the security and stability of affected systems.
Affected Version(s)
Red Hat Enterprise Linux 7 0:15.8-3.el7
Red Hat Enterprise Linux 7 0:15.8-1.el7
Red Hat Enterprise Linux 8 0:15.8-4.el8_9
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database