CVE-2023-40546

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 29, 2024
Updated: Jun 10, 2024
CWE ID 476

Summary

CVE-2023-40546 is a vulnerability affecting the Shim component. When an error occurs during the creation of a new ESL variable, Shim attempts to log an error message. However, the logging function uses a different number of parameters than the format string, resulting in a crash under specific circumstances. This issue can potentially be exploited to cause denial-of-service conditions through unintended crashes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Red Hat Enterprise Linux
  • Fedora Operating System

Affected Vendors

  • Red Hat
  • Fedora Project