CVE-2023-40547High· 8.3▾ TwilightA remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a complet…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 1.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.9%
4.9% → 5.4%
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write primitive and complete system compromise. This flaw is only exploitable during the early boot phase, an attacker needs to perform a Man-in-the-Middle or compromise the boot server to be able to exploit this vulnerability successfully.
shim < 15.8enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0Upgrade past the affected range:
shim 15.8Connected by shared product, vendor, weakness, or advisory.
CVE-2023-40548High· 7.4A buffer overflow was found in Shim in the 32-bit system
CVE-2026-71221High· 7.0A stack out-of-bounds write vulnerability was found in gfs2-utils
CVE-2026-71220High· 7.0A stack out-of-bounds write vulnerability was found in gfs2-utils
CVE-2025-7365High· 7.1A flaw was found in Keycloak
CVE-2025-7519Medium· 6.7A flaw was found in polkit
CVE-2026-71224Medium· 4.7A stack overflow vulnerability was found in gfs2-utils