logo

Critical flaw in Shim bootloader impacts major Linux distros

ID: 742256d9-9bdc-5583-9e27-fe7a4078cee2

STIX ID: report--742256d9-9bdc-5583-9e27-fe7a4078cee2

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-02-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical vulnerability (CVE-2023-40547) in the Shim UEFI bootloader's HTTP boot parsing can produce an out-of-bounds write allowing attackers to execute code before the OS loads, bypassing Secure Boot; the report details discovery, exploitation vectors (remote MiTM, local EFI modification, PXE), and remediation guidance including upgrading to Shim 15.8 and updating the UEFI Secure Boot DBX.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.