CVE-2023-40551 — Out-of-bounds Read in Redhat Shim
Severity
5.1MEDIUMNVD
EPSS
0.0%
top 96.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Description
A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:HExploitability: 0.8 | Impact: 4.2
Affected Packages2 packages
Also affects: Fedora 39, Enterprise Linux 8.0, 9.0