Loading HuntDB...

GHSA-hmxr-46w2-jjwh

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.

Related CVEs

Key Information

GHSA ID
GHSA-hmxr-46w2-jjwh
Published
July 20, 2023 3:30 AM
Last Modified
April 4, 2024 6:17 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.