logo

Linux Distros Hit by RCE Vulnerability in Shim Bootloader

ID: 97ba30da-67d0-56af-a076-784ccf4c6f16

STIX ID: report--97ba30da-67d0-56af-a076-784ccf4c6f16

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-02-07

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Linux shim (CVE-2023-40547) contains an out-of-bounds write in its HTTP response parsing that can lead to remote code execution and full system compromise on UEFI systems; major distributions (Red Hat, Ubuntu, Debian, SUSE) are affected and Red Hat released shim 15.8 to address the issue. Exploitation vectors include man‑in‑the‑middle attacks against HTTP/PXE boot, local modification of EFI variables or EFI partitions, or chain‑loading a vulnerable shim during network boot; vendors disagree on exploitability and no active in-the-wild exploitation is reported in the document.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.