A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory corruption and can lead to a crash or data integrity issues during the boot phase.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade shim-aa64Upgrade shim-ia32Upgrade shim-x64 | May 13, 2024 | Jan 29, 2024 |
| Centos_linux | — | Upgrade mokutilUpgrade shim-unsigned-x64Upgrade shim-x64Upgrade shim-unsigned-ia32Upgrade shim-ia32Upgrade mokutil-debuginfo | Apr 24, 2024 | Jan 29, 2024 |
| Debian | — | Upgrade shim | May 15, 2024 | Jan 29, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade shim | Mar 13, 2024 | Jan 29, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade shim | May 31, 2024 | Jan 29, 2024 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 10, 2024 |
| Oracle_linux | — | Upgrade shim-ia32Upgrade shim-unsigned-x64Upgrade mokutilUpgrade shim-x64Upgrade shim-aa64 | Apr 24, 2024 | Oct 3, 2023 |
| Redhat_linux | — | Upgrade shim-unsigned-ia32Upgrade shim-unsigned-x64Upgrade mokutil-debuginfoUpgrade shim-ia32Upgrade shim-x64Upgrade mokutil | Apr 17, 2024 | Jan 29, 2024 |
| Suse | — | Upgrade shim | Apr 23, 2024 | Jan 29, 2024 |
| Ubuntu | — | Upgrade shim-signedUpgrade shim | Nov 19, 2024 | Jan 29, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub