Critical Bootloader Vulnerability in Shim Impacts Nearly All Linux Distros
Critical Bootloader Vulnerability in Shim Impacts Nearly All Linux Distros
07 February 2024
The maintainers of shim have released version 15.8 to address six security flaws, including a critical bug that could pave the way for remote code execution under specific circumstances.
Tracked as CVE-2023-40547 (CVSS score: 9.8), the vulnerability could be exploited to achieve a Secure Boot bypass. Bill Demirkapi of the Microsoft Security Response Center (MSRC) has been&