Database/Firmware, BMC & network fabric
shim (MZ/PE header parser): Out-of-bounds read parsing MZ binaries
CVE-2023-40551Firmware, BMC & network fabricshim 15.8 batchcurated
Impact
Out-of-bounds read parsing MZ binaries. Leaks memory contents from the pre-boot environment, which can include key material the firmware has not yet cleared.
Who can reach it
Crafted MZ binary loaded via shim.
What to do
shim package update + reboot. Bundle with the rest of the shim 15.8 batch.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.