• News/
  • https://www.bleepingcomputer.com/news/security/critical-flaw-in-shim-bootloader-impacts-major-linux-distros/

Critical flaw in Shim bootloader impacts major Linux distros

BleepingComputer
·
Bill Toulas
·
Published Feb 7, 2024
·
Updated

A critical vulnerability in the Shim Linux bootloader enables attackers to execute code and take control of a target system before the kernel is loaded, bypassing existing security mechanisms. Shim is a small open-source bootloader maintained by Red Hat that is designed to facilitate the Secure Boot process on computers using Unified Extensible Firmware Interface (UEFI). The tool is signed with a Microsoft key accepted by default on most UEFI motherboards that is used to verify the next stage of the boot process, typically loading the GRUB2 bootloader. Shim was created out of necessity to allow open-source projects such as Linux distributions to benefit from Secure Boot's advantages, such as preventing unauthorized or malicious code execution during boot, while still maintaining control over hardware. The new Shim flaw, tracked as CVE-2023-40547, was discovered by Microsoft's security researcher Bill Demirkapi, who first disclosed it on January 24, 2024. The bug resides in the httpboot.c source for Shim, which is used to boot a network image over HTTP.

"When retrieving files via HTTP or related protocols, shim attempts to allocate a buffer to store the received data," reads the commit to fix the bug in httpboot.c. "Unfortunately, this means getting the size from an HTTP header, which can be manipulated to specify a size that's smaller than the received data." "In this case, the code accidentally uses the header for the allocation but the protocol metadata to copy it from th...

Read full article

Affected Software

1 affected component
Red Hat Shim=15.8
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the Shim Linux bootloader that affects several major Linux distributions.

2

What security implications are discussed?

The vulnerability allows attackers to execute code and gain control of a system before the kernel loads, bypassing existing security measures.

3

What products or software are affected?

The affected software includes the Shim bootloader, specifically version 15.8 by Red Hat.

4

Who maintains the Shim bootloader?

The Shim bootloader is maintained by the open-source community and is utilized by various Linux distributions.

5

How can users mitigate this vulnerability?

Users can mitigate this vulnerability by applying the recommended patches and updates provided by their Linux distribution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203