An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-shim-aa64alma-upgrade-shim-ia32alma-upgrade-shim-x64 | May 13, 2024 | Jan 29, 2024 | |
| Centos_linux | — | centos-upgrade-mokutilcentos-upgrade-mokutil-debuginfocentos-upgrade-shim-ia32centos-upgrade-shim-unsigned-ia32centos-upgrade-shim-unsigned-x64centos-upgrade-shim-x64 | Apr 24, 2024 | Jan 29, 2024 |
| Debian | debian-upgrade-shim | May 15, 2024 | Jan 29, 2024 | |
| Huawei Euleros 2_0_sp11 | huawei-euleros-2_0_sp11-upgrade-shim | Mar 13, 2024 | Jan 29, 2024 | |
| Huawei Euleros 2_0_sp12 | huawei-euleros-2_0_sp12-upgrade-shim | May 31, 2024 | Jan 29, 2024 | |
| Nutanix Ahv | nutanix-ahv-upgrade-latest | Jun 5, 2026 | Sep 10, 2024 | |
| Oracle_linux | — | oracle-linux-upgrade-mokutiloracle-linux-upgrade-shim-aa64oracle-linux-upgrade-shim-ia32oracle-linux-upgrade-shim-unsigned-x64oracle-linux-upgrade-shim-x64 | Apr 24, 2024 | Jan 23, 2024 |
| Redhat_linux | redhat-upgrade-mokutilredhat-upgrade-mokutil-debuginforedhat-upgrade-shim-ia32redhat-upgrade-shim-unsigned-ia32redhat-upgrade-shim-unsigned-x64redhat-upgrade-shim-x64 | Apr 17, 2024 | Jan 29, 2024 | |
| Suse | — | suse-upgrade-shim | Apr 23, 2024 | Jan 29, 2024 |
| Ubuntu | ubuntu-upgrade-shimubuntu-upgrade-shim-signed | Nov 19, 2024 | Jan 29, 2024 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jan 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub