CVE-2024-7344
Description
A flaw was found in Howyar UEFI (Unified Extensible Firmware Interface) Application "Reloader". This vulnerability allows execution of unsigned software via a hardcoded path.
Statement
Red Hat components are not directly affected by CVE-2024-7344. However, until the DBX entries are updated on a system, it is possible for an attacker to boot the affected EFI applications even with secure boot protections enabled. Once the affected vendors have released a DBX update, it should be installed through fwupd via LVFS.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.