GPU VulnDB

Database/Firmware, BMC & network fabric

shim (verify_buffer_sbat): Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attacker

CVE-2023-40550Firmware, BMC & network fabricshim 15.8 batchcurated

Impact

Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attacker who can already run in the boot path. Reconnaissance value rather than direct compromise.

Who can reach it

Crafted SBAT metadata in a binary shim is asked to verify.

What to do

shim package update + reboot.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.