CVE-2022-28737
published 2023-07-20CVE-2022-28737: There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.33%
25.3th percentile
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shim | < shim 15.6-1 (bookworm) | shim 15.6-1 (bookworm) |
| msrc | azl3_shim-unsigned-aarch64_15.4-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_shim-unsigned-aarch64_15.8-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_shim-unsigned-x64_15.4-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_shim-unsigned-x64_15.8-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_shim_15.4-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_shim_15.8-5_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| red_hat_bootloader_team | shim | < 15.6 | 15.6 |
| redhat | shim | < 15.6 | 15.6 |
| redhat | shim | >= 0 < 15.6-1~deb11u1 | 15.6-1~deb11u1 |
| redhat | shim | >= 0 < 15.6-1 | 15.6-1 |
| redhat | shim | >= 0 < 15.6-1 | 15.6-1 |
| redhat | shim | >= 0 < 15.6-1 | 15.6-1 |
| redhat | shim | >= 0 < 15.7-0ubuntu1 | 15.7-0ubuntu1 |
| redhat | shim | >= 0 < 15.7-0ubuntu1 | 15.7-0ubuntu1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu4.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
osv·2023-09-08·CVSS 4.5
CVE-2021-3695 [MEDIUM] grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability
Daniel Axtens discovered that specially crafted images could cause a
heap-based out-of-bonds write. A local attacker could possibly use
this to circumvent secure boot protections. (CVE-2021-3695)
Daniel Axtens discovered that specially crafted images could cause
out-of-bonds read and write. A local attacker could possibly use this
to circumvent secure boot protections. (CVE-2021-3696)
Daniel Axtens discovered that specially crafted images could cause
buffer underwrite which allows arbitrary data to be written to a heap.
A local attacker could possibly use this to circumvent secure
boot protections. (CVE-2021-3697)
It was discovered that GRUB2 configuration files were created with
the wrong permissions. An attacker could
GHSA
GHSA-hmxr-46w2-jjwh: There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into acco
ghsa_unreviewed·2023-07-20
CVE-2022-28737 [HIGH] CWE-787 GHSA-hmxr-46w2-jjwh: There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into acco
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.
OSV
CVE-2022-28737: There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into acco
osv·2023-07-20·CVSS 7.8
CVE-2022-28737 [HIGH] CVE-2022-28737: There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into acco
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Ubuntu
GRUB2 vulnerabilities
vendor_ubuntu·2023-09-08·CVSS 4.5
CVE-2022-28737 [MEDIUM] GRUB2 vulnerabilities
Title: GRUB2 vulnerabilities
Summary: Several security issues were fixed in GRUB2.
Daniel Axtens discovered that specially crafted images could cause a
heap-based out-of-bonds write. A local attacker could possibly use
this to circumvent secure boot protections. (CVE-2021-3695)
Daniel Axtens discovered that specially crafted images could cause
out-of-bonds read and write. A local attacker could possibly use this
to circumvent secure boot protections. (CVE-2021-3696)
Daniel Axtens discovered that specially crafted images could cause
buffer underwrite which allows arbitrary data to be written to a heap.
A local attacker could possibly use this to circumvent secure
boot protections. (CVE-2021-3697)
It was discovered that GRUB2 configuration files were created with
the wrong permissions.
Microsoft
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables
vendor_msrc·2023-07-11·CVSS 6.5
CVE-2022-28737 [MEDIUM] CWE-787 There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
canonical: canonical
Customer Action Required: Yes
R
Red Hat
shim: Buffer overflow when loading crafted EFI images
vendor_redhat·2022-06-07·CVSS 6.5
CVE-2022-28737 [MEDIUM] CWE-120 shim: Buffer overflow when loading crafted EFI images
shim: Buffer overflow when loading crafted EFI images
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.
A flaw was found in shim during the handling of EFI executables. A crafted EFI image can lead to an overflow in shim. This flaw allows an attacker to perform an out-of-bounds write in memory. A successful attack can lead to data integrity, confidentiality issues, and arbitrary code execution.
Package: shim (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2022-28737: shim - There's a possible overflow in handle_image() when shim tries to load and execut...
vendor_debian·2022·CVSS 6.5
CVE-2022-28737 [MEDIUM] CVE-2022-28737: shim - There's a possible overflow in handle_image() when shim tries to load and execut...
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.
Scope: local
bookworm: resolved (fixed in 15.6-1)
bullseye: resolved (fixed in 15.6-1~deb11u1)
forky: resolved (fixed in 15.6-1)
sid: resolved (fixed in 15.6-1)
trixie: resolved (fixed in 15.6-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-20
Published