Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-40550

Published: January 25, 2024Last modified: January 25, 2024

Description

An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSshimFixed (15.8-r0)
shim-signedVulnerable (15.7-r0)
StreamshimFixed (15.8-r0)
shim-signedVulnerable (15.7-r0)

References

ON THIS PAGE