Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34094.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-34094
Upstream
Published
2024-01-29T17:15:08Z
Modified
2026-04-21T04:27:02.033806Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
CVE-2023-40550 affecting package shim-unsigned-x64 for versions less than 15.8-1
Details

An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.

References

Affected packages

Azure Linux:2 / shim-unsigned-x64

Package

Name
shim-unsigned-x64
Purl
pkg:rpm/azure-linux/shim-unsigned-x64

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.8-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-34094.json"