REDHAT-BUG-2388707
Published Aug 14, 2025
·Updated
The Fedora Secure Boot CA certificate shipped with shim-x64 in Fedora 38 was expired which could lead to old or invalid signed boot components being loaded.
Affected Software
1 affected component
Fedora shim-x64
Event History
Aug 14, 2025
Data Sourced
via Red Hat·09:04 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2388707?
The severity of REDHAT-BUG-2388707 is high due to the potential for loading outdated or invalid boot components.
2
How do I fix REDHAT-BUG-2388707?
To fix REDHAT-BUG-2388707, update the shim-x64 package to a version with a valid Secure Boot CA certificate.
3
What impact does REDHAT-BUG-2388707 have on system security?
REDHAT-BUG-2388707 can compromise system security by allowing untrusted or unsigned boot components to be executed.
4
Which versions of Fedora are affected by REDHAT-BUG-2388707?
Fedora 38 is specifically affected by REDHAT-BUG-2388707 due to the expired Secure Boot CA certificate in shim-x64.
5
Is there a risk of exploitation associated with REDHAT-BUG-2388707?
Yes, REDHAT-BUG-2388707 poses a risk of exploitation as it may allow unauthorized code to run during the boot process.