First published: Tue Jan 23 2024(Updated: )
An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/shim | <15.8 | 15.8 |
Red Hat Shim | <15.8 | |
Red Hat Fedora | =39 | |
Red Hat Enterprise Linux | =8.0 | |
Red Hat Enterprise Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40550 is classified as an out-of-bounds read vulnerability potentially leading to information disclosure.
To fix CVE-2023-40550, update the Shim package to version 15.8 or later.
CVE-2023-40550 affects the Shim package versions up to 15.8, and specific versions of Fedora and Red Hat Enterprise Linux.
CVE-2023-40550 may be exploited during the system's boot phase to expose sensitive data.
Currently, there are no documented workarounds for CVE-2023-40550; applying the patch is recommended.