RHSA-2024:1883: Important: shim security update
Important: shim security update
Other sources
The shim package contains a first-stage UEFI boot loader that handles chainingto a trusted full boot loader under secure boot environments.Security Fix(es): shim: RCE in http boot support may lead to Secure Boot bypass (CVE-2023-40547) shim: Interger overflow leads to heap buffer overflow in verifysbatsection on 32-bits systems (CVE-2023-40548) shim: Out-of-bounds read printing error messages (CVE-2023-40546) shim: Out-of-bounds read in verifybufferauthenticode() malformed PE file (CVE-2023-40549) shim: Out-of-bound read in verifybuffersbat() (CVE-2023-40550) shim: out of bounds read when parsing MZ binaries (CVE-2023-40551) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/shimto a version that resolves this vulnerability.Fixed in 15.8-2.el8 - Upgrade
Upgrade
redhat/shim-ia32to a version that resolves this vulnerability.Fixed in 15.8-2.el8 - Upgrade
Upgrade
redhat/shim-x64to a version that resolves this vulnerability.Fixed in 15.8-2.el8 - Upgrade
Upgrade
redhat/shim-aa64to a version that resolves this vulnerability.Fixed in 15.8-2.el8.aa - Upgrade
Upgrade
redhat/shim-unsigned-x64to a version that resolves this vulnerability.Fixed in 15.8-2.el8
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1883?
The severity of RHSA-2024:1883 is categorized as Important.
How do I fix RHSA-2024:1883?
To address RHSA-2024:1883, update the shim package to version 15.8-2.el8 or newer.
What vulnerability does RHSA-2024:1883 address?
RHSA-2024:1883 addresses a remote code execution (RCE) vulnerability in the http boot support of the shim package.
Which systems are affected by RHSA-2024:1883?
RHSA-2024:1883 affects multiple versions of Red Hat Enterprise Linux, including ARM 64 and x86_64 architectures.
Is there a workaround for RHSA-2024:1883?
While an immediate workaround is not specified, it is recommended to apply the security update as soon as possible.