CVE-2024-7344

Description

A flaw was found in Howyar UEFI (Unified Extensible Firmware Interface) Application "Reloader". This vulnerability allows execution of unsigned software via a hardcoded path.

Statement

Red Hat components are not directly affected by CVE-2024-7344. However, until the DBX entries are updated on a system, it is possible for an attacker to boot the affected EFI applications even with secure boot protections enabled. Once the affected vendors have released a DBX update, it should be installed through fwupd via LVFS.

Frequently Asked Questions

Want to get errata notifications? Sign up here.