Database/Firmware, BMC & network fabric
shim (verify_sbat_section): Integer overflow leading to heap overflow while verifying the SBAT section on 32-bit
CVSS 7.4CVE-2023-40548Firmware, BMC & network fabricshim 15.8 batchcurated
Impact
Integer overflow leading to heap overflow while verifying the SBAT section on 32-bit systems. The irony matters operationally: SBAT is the mechanism meant to revoke vulnerable bootloaders, and parsing it is itself exploitable.
Who can reach it
Crafted binary presented to shim on a 32-bit EFI implementation. Rare on server-class GPU hardware, common on 32-bit-EFI edge and embedded boxes.
What to do
shim package update + reboot. Low priority on x86-64 server fleets, real on any 32-bit-EFI hardware you still operate.
References
Related entries
- Dell OMSA: unauthenticated SSRF turns the management agent into a proxy into the management VLANCVE-2026-81446 · Dell OpenManage Server Administrator (SSRF, unauthenticated)High
- Intel SGX (L1 terminal fault on enclave pages): Speculative execution lets code outside an enclave read the enclave'sCVE-2018-3615 · Intel SGX (L1 terminal fault on enclave pages)High
- AMD Secure Processor Secure OS - memory buffer checking: A malicious trusted application can read and write the ASPCVE-2022-23817 · AMD Secure Processor Secure OS - memory buffer checkingHigh
- Lenovo XClarity Controller (XCC) - LDAP/AD authorization: When XCC is configured to authenticate against ActiveCVE-2023-29057 · Lenovo XClarity Controller (XCC) - LDAP/AD authorizationHigh
- BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmwareCVE-2023-29164 · BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmware…High
- Linux bnxt_en driver (bnxt_fill_hw_rss_tbl): Memory out-of-bounds in the RSS indirection-table path of the Broadcom NICCVE-2024-44933 · Linux bnxt_en driver (bnxt_fill_hw_rss_tbl)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.