PT-2023-8436 · Shim+7 · Shim+7
Marco Benatto
·
Published
2023-08-26
·
Updated
2025-03-07
·
CVE-2023-40547
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Shim versions prior to 15.8
Description
A remote code execution vulnerability was found in Shim, a core component of secure boot in Linux. The vulnerability allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, and an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully. The estimated number of potentially affected devices worldwide is in the millions.
Recommendations
Update to Shim version 15.8 or later to address the vulnerability.
As a temporary workaround, consider restricting access to the HTTP boot support feature in Shim until a patch is available.
Avoid using Shim with Secure Boot enabled until the issue is resolved.
Update the UEFI Secure Boot DBX to include hashes of the vulnerable Shim software and sign the updated version with a valid key.
Exploit
Fix
RCE
Origin Validation Error
Memory Corruption
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Red Hat
Red Os
Shim
Suse
Windows