Database/Firmware, BMC & network fabric
shim (verify_sbat_section): Integer overflow leading to heap overflow while verifying the SBAT section on 32-bit
CVE-2023-40548Firmware, BMC & network fabricshim 15.8 batchcurated
Impact
Integer overflow leading to heap overflow while verifying the SBAT section on 32-bit systems. The irony matters operationally: SBAT is the mechanism meant to revoke vulnerable bootloaders, and parsing it is itself exploitable.
Who can reach it
Crafted binary presented to shim on a 32-bit EFI implementation. Rare on server-class GPU hardware, common on 32-bit-EFI edge and embedded boxes.
What to do
shim package update + reboot. Low priority on x86-64 server fleets, real on any 32-bit-EFI hardware you still operate.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.