Integer overflow in Shim - CVE-2023-40548
Published: February 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow within the verify_sbat_section on 32-bits systems. A remote attacker can pass a specially crafted PE binary to the application, trigger an integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Anolis OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
openEuler
Juniper Secure Analytics (JSA)
Storage Resource Manager
Dell EMC Storage Monitoring and Reporting (SMR)
Dell Secure Connect Gateway
IBM Power Hardware Management Console (HMC)
IBM Qradar SIEM
Dell EMC VxRail Appliance
shim-debugsource
shim
shim-debuginfo
shim-x64
shim-aa64
shim-signed (Red Hat package)
shim-ia32
mokutil
shim (Red Hat package)
shim-unsigned-x64 (Red Hat package)
shim-unsigned-aarch64 (Red Hat package)
shim-unsigned-x64
shim-unsigned-ia32
How to mitigate CVE-2023-40548
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Dell Secure Connect Gateway - update to 5.24.00.14
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF03
Dell EMC VxRail Appliance - update to 8.0.212
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP2, 10.3.1060.0
shim-debugsource - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15.6-19
shim - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15.6-19
shim-debuginfo - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15.6-19
shim-x64 - addressed in versions 15.7-3, 15.8-1.0.1, 15.8-2.0.1
shim-aa64 - addressed in versions 15.7-3, 15.8-1.0.1, 15.8-2.0.1
shim-signed (Red Hat package) - update to 15.8-1.el7
shim-ia32 - addressed in versions 15.8-1.0.1, 15.8-2.0.1
mokutil - update to 15.8-1.0.1
shim (Red Hat package) - addressed in versions 15.8-2.el8, 15.8-2.el8_2, 15.8-2.el8_4, 15.8-2.el8_6, 15.8-3.el7, 15.8-3.el9, 15.8-3.el9_2, 15.8-4.el8_9, 15.8-4.el9_3
shim-unsigned-x64 (Red Hat package) - addressed in versions 15.8-2.el8, 15.8-2.el9
shim-unsigned-aarch64 (Red Hat package) - update to 15.8-2.el9
shim-unsigned-x64 - addressed in versions 15.8-2.0.1, 15.8-3.0.1
shim-unsigned-ia32 - update to 15.8-3.0.1
shim - addressed in versions 15.8-25.30.1, 15.8-150100.3.38.1
shim-debugsource - update to 15.8-150100.3.38.1
shim-debuginfo - update to 15.8-150100.3.38.1
External References
Related Security Bulletins
- Multiple vulnerabilities in UEFI shim loader
- openEuler 22.03 LTS update for shim
- openEuler 22.03 LTS SP1 update for shim
- openEuler 22.03 LTS SP2 update for shim
- openEuler 22.03 LTS SP3 update for shim
- Red Hat Enterprise Linux 8 update for shim
- Red Hat Enterprise Linux 9.0 Extended Update Support update for shim
- Red Hat Enterprise Linux 8 update for shim
- Red Hat Enterprise Linux 9.2 Extended Update Support update for shim
- Red Hat Enterprise Linux 8 update for shim
- Red Hat Enterprise Linux 8 update for shim
- Red Hat Enterprise Linux 9 update for shim
- Red Hat Enterprise Linux 7 update for shim
- Red Hat Enterprise Linux 8 update for shim
- SUSE update for shim
- SUSE update for shim
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in IBM Power HMC
- Anolis OS update for shim
- Anolis OS update for shim and shim-signed
- Anolis OS update for shim-unsigned-x64
- Anolis OS update for shim