Database/Firmware, BMC & network fabric
shim (mok.c mirror_one_esl): NULL pointer dereference while printing an error message stops the node from booting
CVSS 6.1CVE-2023-40546Firmware, BMC & network fabricshim 15.8 batchcurated
Impact
NULL pointer dereference while printing an error message stops the node from booting. On a fleet this is a denial of service you cannot fix over SSH - it needs console or BMC access per affected node, which is expensive at scale.
Who can reach it
Requires attacker-influenced MOK/ESL data on the node.
What to do
shim package update + reboot. Availability-only, so it can ride a normal maintenance window rather than an emergency one.
References
Related entries
- Linux kernel (drivers/pci/switch): If a userspace process is holding the Switchtec management character device openCVE-2023-52617 · Linux kernel (drivers/pci/switch)Medium
- Avocent DSR2030 / SVIP1020 KVM-over-IP appliance: A reflected XSS in the appliance's web interface lets an attackerCVE-2024-34923 · Avocent DSR2030 / SVIP1020 KVM-over-IP applianceMedium
- Intel Xeon 6 E-core with TDX or SGX: Improper restriction of software interfaces to hardware features on Xeon 6 E-coreCVE-2024-48869 · Intel Xeon 6 E-core with TDX or SGXMedium
- Intel Ethernet E810 Series and Ethernet 700 Series firmware: Out-of-bounds write in firmware across both the E810 lineCVE-2022-36382 · Intel Ethernet E810 Series and Ethernet 700 Series firmwareMedium
- Intel processors with SGX (shared resource isolation): Improper isolation of shared microarchitectural resources lets aCVE-2022-38090 · Intel processors with SGX (shared resource isolation)Medium
- Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit): The dynamic-counter netlink setter bounded itsCVE-2022-49199 · Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.