#VU86241 NULL pointer dereference in Shim - CVE-2023-40546
Published: February 7, 2024
Shim
Red Hat Bootloader Team
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the mirror_one_esl() function in mok.c while creating a new ESL variable. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.