Critical Boot Loader Vulnerability in Shim Impacts Nearly All Linux Distros
ID: 1fd981b4-2b39-5b79-8e3d-f1d2b43e3faa
STIX ID: report--1fd981b4-2b39-5b79-8e3d-f1d2b43e3faa
Feed Name: The Hacker News
Threat Score
shim 15.8 fixes six vulnerabilities—including a critical HTTP boot parsing flaw (CVE-2023-40547, CVSS 9.8) that can lead to Secure Boot bypass and pre-kernel remote code execution. The issue affects widely used signed Linux boot loaders across major distributions and could be exploited via MitM or local modification of the EFI partition to install persistent bootkits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
