CVE-2023-5342: Shim: expired secure boot certificate
The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.
Other sources
The Fedora Secure Boot CA certificate shipped with shim-x64 in Fedora 38 was expired which could lead to old or invalid signed boot components being loaded.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5342?
CVE-2023-5342 is considered a moderate severity vulnerability due to the potential for the loading of invalid signed boot components.
How do I fix CVE-2023-5342?
To fix CVE-2023-5342, update the shim package in Fedora to the latest version that has a valid Secure Boot CA certificate.
What are the consequences of CVE-2023-5342?
The consequences of CVE-2023-5342 include the risk of booting with outdated or incorrect signed components, leading to a compromised system.
Which software is affected by CVE-2023-5342?
CVE-2023-5342 specifically affects the Fedora shim-x64 package.
Is there a workaround for CVE-2023-5342?
There is no known effective workaround for CVE-2023-5342; updating the affected software is the recommended action.