CVE-2023-40551: Shim: out of bounds read when parsing mz binaries
A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.
Other sources
rhboot shim is vulnerable to a denial of service, caused by an out-of-bounds read flaw when parsing MZ binaries. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause the application to crash or obtain sensitive information.
— IBM
When handling MZ binaries, crafted PE headers can lead to a out-of-bounds read, causing shim to crash and possibly exposing sensitive information.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40551?
The severity of CVE-2023-40551 is classified as high due to the potential for crashes and sensitive data exposure.
How do I fix CVE-2023-40551?
To fix CVE-2023-40551, update the shim package to version 15.8 or later.
What software is affected by CVE-2023-40551?
CVE-2023-40551 affects shim versions below 15.8, Red Hat Enterprise Linux 8.0, 9.0, and Fedora 39.
What kind of vulnerability is CVE-2023-40551?
CVE-2023-40551 is an out-of-bounds read vulnerability that can lead to a crash or exposure of sensitive data.
What can be the consequences of CVE-2023-40551?
The consequences of CVE-2023-40551 may include system crashes and potential exposure of sensitive information during the boot process.