- 発行日:
- 2024-04-18
- 更新日:
- 2024-04-18
RHSA-2024:1902 - Security Advisory
概要
Important: shim security update
タイプ/重大度
Security Advisory: Important
Red Hat Insights パッチ分析
このアドバイザリーの影響を受けるシステムを特定し、修正します。
トピック
An update for shim is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
説明
The shim package contains a first-stage UEFI boot loader that handles chaining
to a trusted full boot loader under secure boot environments.
Security Fix(es):
- shim: RCE in http boot support may lead to Secure Boot bypass (CVE-2023-40547)
- shim: Interger overflow leads to heap buffer overflow in verify_sbat_section
on 32-bits systems (CVE-2023-40548)
- shim: Out-of-bounds read printing error messages (CVE-2023-40546)
- shim: Out-of-bounds read in verify_buffer_authenticode() malformed PE file
(CVE-2023-40549)
- shim: Out-of-bound read in verify_buffer_sbat() (CVE-2023-40550)
- shim: out of bounds read when parsing MZ binaries (CVE-2023-40551)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
影響を受ける製品
- Red Hat Enterprise Linux for x86_64 8 x86_64
- Red Hat Enterprise Linux for ARM 64 8 aarch64
修正
- BZ - 2234589 - CVE-2023-40547 shim: RCE in http boot support may lead to Secure Boot bypass
- BZ - 2241782 - CVE-2023-40548 shim: Interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems
- BZ - 2241796 - CVE-2023-40546 shim: Out-of-bounds read printing error messages
- BZ - 2241797 - CVE-2023-40549 shim: Out-of-bounds read in verify_buffer_authenticode() malformed PE file
- BZ - 2259915 - CVE-2023-40550 shim: Out-of-bound read in verify_buffer_sbat()
- BZ - 2259918 - CVE-2023-40551 shim: out of bounds read when parsing MZ binaries
Red Hat Enterprise Linux for x86_64 8
SRPM | |
---|---|
shim-15.8-4.el8_9.src.rpm | SHA-256: e9c38735d1d60307eff79022044b778f5965cfc7ded5ca6f23f79210fa971e89 |
x86_64 | |
shim-ia32-15.8-4.el8_9.x86_64.rpm | SHA-256: 82e900462f2c3ba550fb2261849b2328686b981244813c97dd68d36f9ddf858e |
shim-x64-15.8-4.el8_9.x86_64.rpm | SHA-256: d0b677831e9d6897c25e6322908d73f9b1043d88e8773ff3facf89e85771f000 |
Red Hat Enterprise Linux for ARM 64 8
SRPM | |
---|---|
shim-15.8-4.el8_9.src.rpm | SHA-256: e9c38735d1d60307eff79022044b778f5965cfc7ded5ca6f23f79210fa971e89 |
aarch64 | |
shim-aa64-15.8-4.el8_9.aarch64.rpm | SHA-256: 455afe58a185c181066cee426c0257c1e2e2230d1745285eb952b3817cab8891 |
Red Hat のセキュリティーに関する連絡先は secalert@redhat.com です。 連絡先の詳細は https://access.redhat.com/security/team/contact/ をご覧ください。