Database/Firmware, BMC & network fabric
shim (handle_image PE loader): Buffer overflow in shim's own image loader
Impact
Buffer overflow in shim's own image loader. Because shim is the Microsoft-signed component every Linux node chains through, a bug here is worse than a GRUB bug: it bypasses Secure Boot on any machine that trusts the Microsoft 3rd-party CA, regardless of which distro's GRUB sits behind it.
Who can reach it
Local, with the ability to present a crafted EFI image to shim.
What to do
shim package update + reboot per node. Revoking the old shim means an SBAT generation bump pushed by Microsoft/vendor updates rather than a dbx entry - track SBAT levels, not just package versions, or you will believe you are fixed when you are not.
References
Related entries
- Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use): UsbCoreDxe uses pointers it was handed without establishing theyCVE-2022-29275 · Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use)High
- Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs): SMI functions in the AHCI/SATA driver consume untrusted inputsCVE-2022-29276 · Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs)High
- Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks): The NVMe driver's pointer validation is wrong, allowingCVE-2022-29278 · Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks)High
- Insyde InsydeH2O (SdHostDriver and SdMmcDevice, untrusted pointer use): One advisory covering both SD layers: untrustedCVE-2022-29279 · Insyde InsydeH2O (SdHostDriver and SdMmcDevice, untrusted pointer use)High
- Insyde InsydeH2O (PnpSmm initialization, SMRAM corruption via later PNP SMIs): An initialization-order defect: PnpSmm'sCVE-2022-30771 · Insyde InsydeH2O (PnpSmm initialization, SMRAM corruption via later PNP SMIs)High
- Insyde InsydeH2O (PnpSmm function 0x52, SMBIOS write address manipulation): PnpSmm function 0x52 takes an addressCVE-2022-30772 · Insyde InsydeH2O (PnpSmm function 0x52, SMBIOS write address manipulation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.