Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-40548
HistoryJan 29, 2024 - 3:15 p.m.

Heap overflow

2024-01-2915:15:00
PRIOn knowledge base
www.prio-n.com
6
buffer overflow
shim
32-bit system
user-controlled value
pe binary
heap-based
memory corruption
crash
boot phase
data integrity issues

7.7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.0%

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory corruption and can lead to a crash or data integrity issues during the boot phase.

CPENameOperatorVersion
fedoraeq39
shimlt15.8
shimeq15.8 rc1

7.7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

28.0%