Integer Overflow or Wraparound Affecting shim-ia32 package, versions <0:15.8-4.el8_9


Severity

Recommended
high

Based on CentOS security rating

    Threat Intelligence

    EPSS
    0.06% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-CENTOS8-SHIMIA32-6189317
  • published 25 Jan 2024
  • disclosed 3 Oct 2023

How to fix?

Upgrade Centos:8 shim-ia32 to version 0:15.8-4.el8_9 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream shim-ia32 package and not the shim-ia32 package as distributed by Centos. See How to fix? for Centos:8 relevant fixed versions and status.

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer overflow. This flaw causes memory corruption and can lead to a crash or data integrity issues during the boot phase.

CVSS Scores

version 3.1
Expand this section

NVD

7.4 high
Expand this section

Red Hat

6.2 medium
Expand this section

SUSE

6.7 medium