Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-35257.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-35257
Upstream
Published
2024-01-29T17:15:08Z
Modified
2026-04-21T04:27:57.766915Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
CVE-2023-40550 affecting package shim for versions less than 15.8-3
Details

An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.

References

Affected packages

Azure Linux:3 / shim

Package

Name
shim
Purl
pkg:rpm/azure-linux/shim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
15.8-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-35257.json"