#VU86238 Out-of-bounds read in Shim - CVE-2023-40549
Published: February 7, 2024
Shim
Red Hat Bootloader Team
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the verify_buffer_authenticode() function when parsing PE binary. A remote attacker can pass a specially crafted PE binary to the loader, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.