Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-40551

Published: January 25, 2024Last modified: January 25, 2024

Description

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.

Severity score breakdown

ParameterValue
Base score5.1
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredHIGH
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSshimFixed (15.8-r0)
shim-signedVulnerable (15.7-r0)
StreamshimFixed (15.8-r0)
shim-signedVulnerable (15.7-r0)

References

ON THIS PAGE