{"id":"RHSA-2024:1959","summary":"Red Hat Security Advisory: shim security update","modified":"2026-06-27T10:19:24Z","published":"2024-10-01T13:45:19Z","upstream":["CVE-2023-40546","CVE-2023-40547","CVE-2023-40548","CVE-2023-40549","CVE-2023-40550","CVE-2023-40551"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2024:1959"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2234589"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2241782"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2241796"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2241797"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259915"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2259918"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/RHEL-2155"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/RHEL-4382"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/RHEL-4390"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1959.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-40546"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-40546"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40546"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-40547"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-40547"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40547"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-40548"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-40548"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40548"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-40549"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-40549"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40549"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-40550"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-40550"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40550"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2023-40551"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2023-40551"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-40551"}],"affected":[{"package":{"name":"mokutil","ecosystem":"Red Hat:enterprise_linux:7::client","purl":"pkg:rpm/redhat/mokutil"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"mokutil-debuginfo","ecosystem":"Red Hat:enterprise_linux:7::client","purl":"pkg:rpm/redhat/mokutil-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim","ecosystem":"Red Hat:enterprise_linux:7::client","purl":"pkg:rpm/redhat/shim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-ia32","ecosystem":"Red Hat:enterprise_linux:7::client","purl":"pkg:rpm/redhat/shim-ia32"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-signed","ecosystem":"Red Hat:enterprise_linux:7::client","purl":"pkg:rpm/redhat/shim-signed"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-unsigned-ia32","ecosystem":"Red Hat:enterprise_linux:7::client","purl":"pkg:rpm/redhat/shim-unsigned-ia32"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-unsigned-x64","ecosystem":"Red Hat:enterprise_linux:7::client","purl":"pkg:rpm/redhat/shim-unsigned-x64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-x64","ecosystem":"Red Hat:enterprise_linux:7::client","purl":"pkg:rpm/redhat/shim-x64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"mokutil","ecosystem":"Red Hat:enterprise_linux:7::server","purl":"pkg:rpm/redhat/mokutil"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"mokutil-debuginfo","ecosystem":"Red Hat:enterprise_linux:7::server","purl":"pkg:rpm/redhat/mokutil-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim","ecosystem":"Red Hat:enterprise_linux:7::server","purl":"pkg:rpm/redhat/shim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-ia32","ecosystem":"Red Hat:enterprise_linux:7::server","purl":"pkg:rpm/redhat/shim-ia32"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-signed","ecosystem":"Red Hat:enterprise_linux:7::server","purl":"pkg:rpm/redhat/shim-signed"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-unsigned-ia32","ecosystem":"Red Hat:enterprise_linux:7::server","purl":"pkg:rpm/redhat/shim-unsigned-ia32"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-unsigned-x64","ecosystem":"Red Hat:enterprise_linux:7::server","purl":"pkg:rpm/redhat/shim-unsigned-x64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-x64","ecosystem":"Red Hat:enterprise_linux:7::server","purl":"pkg:rpm/redhat/shim-x64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"mokutil","ecosystem":"Red Hat:enterprise_linux:7::workstation","purl":"pkg:rpm/redhat/mokutil"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"mokutil-debuginfo","ecosystem":"Red Hat:enterprise_linux:7::workstation","purl":"pkg:rpm/redhat/mokutil-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim","ecosystem":"Red Hat:enterprise_linux:7::workstation","purl":"pkg:rpm/redhat/shim"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-ia32","ecosystem":"Red Hat:enterprise_linux:7::workstation","purl":"pkg:rpm/redhat/shim-ia32"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-signed","ecosystem":"Red Hat:enterprise_linux:7::workstation","purl":"pkg:rpm/redhat/shim-signed"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-unsigned-ia32","ecosystem":"Red Hat:enterprise_linux:7::workstation","purl":"pkg:rpm/redhat/shim-unsigned-ia32"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-unsigned-x64","ecosystem":"Red Hat:enterprise_linux:7::workstation","purl":"pkg:rpm/redhat/shim-unsigned-x64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-3.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}},{"package":{"name":"shim-x64","ecosystem":"Red Hat:enterprise_linux:7::workstation","purl":"pkg:rpm/redhat/shim-x64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:15.8-1.el7"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2024:1959.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}