Database/Firmware, BMC & network fabric
shim (handle_image PE loader): Buffer overflow in shim's own image loader
Impact
Buffer overflow in shim's own image loader. Because shim is the Microsoft-signed component every Linux node chains through, a bug here is worse than a GRUB bug: it bypasses Secure Boot on any machine that trusts the Microsoft 3rd-party CA, regardless of which distro's GRUB sits behind it.
Who can reach it
Local, with the ability to present a crafted EFI image to shim.
What to do
shim package update + reboot per node. Revoking the old shim means an SBAT generation bump pushed by Microsoft/vendor updates rather than a dbx entry - track SBAT levels, not just package versions, or you will believe you are fixed when you are not.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.