- 発行日:
- 2024-04-18
- 更新日:
- 2024-04-18
RHSA-2024:1903 - Security Advisory
概要
Important: shim bug fix update
タイプ/重大度
Security Advisory: Important
Red Hat Insights パッチ分析
このアドバイザリーの影響を受けるシステムを特定し、修正します。
トピック
An update for shim is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
説明
The shim package contains a first-stage UEFI boot loader that handles chaining
to a trusted full boot loader under secure boot environments.
Security Fix(es):
- shim: RCE in http boot support may lead to Secure Boot bypass (CVE-2023-40547)
- shim: Interger overflow leads to heap buffer overflow in verify_sbat_section
on 32-bits systems (CVE-2023-40548)
- shim: Out-of-bounds read printing error messages (CVE-2023-40546)
- shim: Out-of-bounds read in verify_buffer_authenticode() malformed PE file
(CVE-2023-40549)
- shim: Out-of-bound read in verify_buffer_sbat() (CVE-2023-40550)
- shim: out of bounds read when parsing MZ binaries (CVE-2023-40551)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
影響を受ける製品
- Red Hat Enterprise Linux for x86_64 9 x86_64
- Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
- Red Hat Enterprise Linux Server - AUS 9.4 x86_64
- Red Hat Enterprise Linux for ARM 64 9 aarch64
- Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
- Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
- Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
修正
- BZ - 2234589 - CVE-2023-40547 shim: RCE in http boot support may lead to Secure Boot bypass
- BZ - 2241782 - CVE-2023-40548 shim: Interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems
- BZ - 2241796 - CVE-2023-40546 shim: Out-of-bounds read printing error messages
- BZ - 2241797 - CVE-2023-40549 shim: Out-of-bounds read in verify_buffer_authenticode() malformed PE file
- BZ - 2259915 - CVE-2023-40550 shim: Out-of-bound read in verify_buffer_sbat()
- BZ - 2259918 - CVE-2023-40551 shim: out of bounds read when parsing MZ binaries
Red Hat Enterprise Linux for x86_64 9
SRPM | |
---|---|
shim-15.8-4.el9_3.src.rpm | SHA-256: 74a732f4e09dcb9cfd0d6e13f145817e8955c7aa32f8d0354f8ad7f030438e83 |
x86_64 | |
shim-x64-15.8-4.el9_3.x86_64.rpm | SHA-256: 214fd552dbe5c0105532ada68341b0f4d4d0562ab9e631abd95a6eb13bb57f2c |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4
SRPM | |
---|---|
shim-15.8-4.el9_3.src.rpm | SHA-256: 74a732f4e09dcb9cfd0d6e13f145817e8955c7aa32f8d0354f8ad7f030438e83 |
x86_64 | |
shim-x64-15.8-4.el9_3.x86_64.rpm | SHA-256: 214fd552dbe5c0105532ada68341b0f4d4d0562ab9e631abd95a6eb13bb57f2c |
Red Hat Enterprise Linux Server - AUS 9.4
SRPM | |
---|---|
shim-15.8-4.el9_3.src.rpm | SHA-256: 74a732f4e09dcb9cfd0d6e13f145817e8955c7aa32f8d0354f8ad7f030438e83 |
x86_64 | |
shim-x64-15.8-4.el9_3.x86_64.rpm | SHA-256: 214fd552dbe5c0105532ada68341b0f4d4d0562ab9e631abd95a6eb13bb57f2c |
Red Hat Enterprise Linux for ARM 64 9
SRPM | |
---|---|
shim-15.8-4.el9_3.src.rpm | SHA-256: 74a732f4e09dcb9cfd0d6e13f145817e8955c7aa32f8d0354f8ad7f030438e83 |
aarch64 | |
shim-aa64-15.8-4.el9_3.aarch64.rpm | SHA-256: c7baf345f9985a1da038edc2bc9265a2da973556f5dbf26a0a631bf9c6dff75e |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4
SRPM | |
---|---|
shim-15.8-4.el9_3.src.rpm | SHA-256: 74a732f4e09dcb9cfd0d6e13f145817e8955c7aa32f8d0354f8ad7f030438e83 |
aarch64 | |
shim-aa64-15.8-4.el9_3.aarch64.rpm | SHA-256: c7baf345f9985a1da038edc2bc9265a2da973556f5dbf26a0a631bf9c6dff75e |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4
SRPM | |
---|---|
shim-15.8-4.el9_3.src.rpm | SHA-256: 74a732f4e09dcb9cfd0d6e13f145817e8955c7aa32f8d0354f8ad7f030438e83 |
x86_64 | |
shim-x64-15.8-4.el9_3.x86_64.rpm | SHA-256: 214fd552dbe5c0105532ada68341b0f4d4d0562ab9e631abd95a6eb13bb57f2c |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4
SRPM | |
---|---|
shim-15.8-4.el9_3.src.rpm | SHA-256: 74a732f4e09dcb9cfd0d6e13f145817e8955c7aa32f8d0354f8ad7f030438e83 |
aarch64 | |
shim-aa64-15.8-4.el9_3.aarch64.rpm | SHA-256: c7baf345f9985a1da038edc2bc9265a2da973556f5dbf26a0a631bf9c6dff75e |
Red Hat のセキュリティーに関する連絡先は secalert@redhat.com です。 連絡先の詳細は https://access.redhat.com/security/team/contact/ をご覧ください。