cvedb.io
CVE-2023-40548
HIGH · CVSS 7.4
EPSS exploitation probability: 0%
Published 2024-01-29T15:15:08.893 · Last modified 2026-06-26T10:16:22.183

Summary

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory corruption and can lead to a crash or data integrity issues during the boot phase.

Affected products

redhat — shim

Does this affect you?

Add your gear to cvedb and we'll alert you only when redhat ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.