A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory corruption and can lead to a crash or data integrity issues during the boot phase.
2024-01-29T15:15:08.893
2024-11-21T08:19:41.833
Modified
CVSSv3.1: 7.4 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | shim | < 15.8 | Yes |
Application | redhat | shim | 15.8 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |