Database/Firmware, BMC & network fabric
shim (verify_buffer_sbat): Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attacker
CVE-2023-40550Firmware, BMC & network fabricshim 15.8 batchcurated
Impact
Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attacker who can already run in the boot path. Reconnaissance value rather than direct compromise.
Who can reach it
Crafted SBAT metadata in a binary shim is asked to verify.
What to do
shim package update + reboot.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.