Bug 1215103 (CVE-2023-40551) - VUL-0: CVE-2023-40551: shim: pe-relocate: Fix bounds check for MZ binaries
Summary: VUL-0: CVE-2023-40551: shim: pe-relocate: Fix bounds check for MZ binaries
Status: NEW
Alias: CVE-2023-40551
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Tseng
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/377598/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-40551:4.4:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-09-07 07:05 UTC by Marcus Meissner
Modified: 2024-07-12 09:30 UTC (History)
9 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
shim commit CVE-2023-40551 from keybase (1.27 KB, text/plain)
2023-12-18 06:53 UTC, Tseng
Details
CVE-2023-40551 codes from keybase (2.74 KB, patch)
2023-12-21 14:46 UTC, Tseng
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Comment 3 Marcus Meissner 2023-12-06 10:03:19 UTC
CRD: 2023-12-12
Comment 6 Tseng 2023-12-18 06:53:24 UTC
Created attachment 871411 [details]
shim commit CVE-2023-40551 from keybase
Comment 7 Tseng 2023-12-21 14:46:13 UTC
Created attachment 871511 [details]
CVE-2023-40551 codes from keybase
Comment 8 Marcus Meissner 2024-01-11 12:45:34 UTC
embargo end was shifted again:

CRD: 2024-01-23
Comment 9 Marcus Meissner 2024-01-24 10:22:16 UTC
is public

https://github.com/rhboot/shim/releases/tag/15.8
Comment 10 Tseng 2024-01-30 02:02:33 UTC
This CVE was revealed on January 23, 2024 in a new shim-15.8 release.
At the same time, a shim-15.8 update has been submitted to Factory. Please refer https://build.opensuse.org/request/show/1142576
Comment 13 Steve Moring 2024-02-22 12:52:41 UTC
(In reply to Tseng from comment #10)
> This CVE was revealed on January 23, 2024 in a new shim-15.8 release.
> At the same time, a shim-15.8 update has been submitted to Factory. Please
> refer https://build.opensuse.org/request/show/1142576

I can't see the status of this build request, would it be possible for someone with access to let me know where this stands?
Comment 14 Marcus Meissner 2024-02-22 12:55:08 UTC
the shim 5.18 for SLE is in the build pipeline.

As it needs to be signed by Microsoft, there are some additional steps required which take an unknown amount of time.
Comment 15 Steve Moring 2024-03-07 18:34:18 UTC
(In reply to Marcus Meissner from comment #14)
> the shim 5.18 for SLE is in the build pipeline.
> 
> As it needs to be signed by Microsoft, there are some additional steps
> required which take an unknown amount of time.

Hi Marcus,

Should we expect another few weeks, or days?
Comment 16 Johannes Segitz 2024-03-08 12:11:37 UTC
review requests are in 
https://github.com/rhboot/shim-review/issues/393
https://github.com/rhboot/shim-review/issues/394
currently there's quite a bit of activity in the repo, but I would rather assume weeks instead of days
Comment 17 Joe Fruchey 2024-04-04 21:54:05 UTC
Hi Johannes,

There was ongoing activity in both Github issues until about 2 weeks ago. Are we still awaiting further review from Microsoft?
Comment 18 Marcus Meissner 2024-04-05 07:02:29 UTC
We still wait for the community reviewers to review and approve. (until the issue has an "approved" label)

Only after that we will go to MS for signing.
Comment 19 Steven Moring 2024-04-05 12:24:11 UTC
(In reply to Marcus Meissner from comment #18)
> We still wait for the community reviewers to review and approve. (until the
> issue has an "approved" label)
> 
> Only after that we will go to MS for signing.

I realize that this is a slow laborious process and we don't do it often.  Is there any way that we can update customers on the progress publicly?
Comment 20 Johannes Segitz 2024-04-08 11:31:51 UTC
it's not a secret process. The customer can check the github issues linked above or we can communicate it to them
Comment 21 Steve Moring 2024-04-08 12:50:54 UTC
(In reply to Johannes Segitz from comment #20)
> it's not a secret process. The customer can check the github issues linked
> above or we can communicate it to them

Thank you for asking within the github about what we're waiting on, it'd been 3 weeks since any updates were provided.
Comment 22 Maintenance Automation 2024-04-22 12:30:19 UTC
SUSE-SU-2024:1368-1: An update that solves seven vulnerabilities, contains one feature and has five security fixes can now be installed.

Category: security (important)
Bug References: 1198101, 1205588, 1205855, 1210382, 1213945, 1215098, 1215099, 1215100, 1215101, 1215102, 1215103, 1219460
CVE References: CVE-2022-28737, CVE-2023-40546, CVE-2023-40547, CVE-2023-40548, CVE-2023-40549, CVE-2023-40550, CVE-2023-40551
Jira References: PED-922
Maintenance Incident: [SUSE:Maintenance:32617](https://smelt.suse.de/incident/32617/)
Sources used:
openSUSE Leap 15.3 (src):
 shim-15.8-150300.4.20.2, efitools-1.9.2-150300.7.3.1
openSUSE Leap Micro 5.3 (src):
 shim-15.8-150300.4.20.2
openSUSE Leap Micro 5.4 (src):
 shim-15.8-150300.4.20.2
openSUSE Leap 15.5 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Micro for Rancher 5.3 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Micro 5.3 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Micro for Rancher 5.4 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Micro 5.4 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Micro 5.5 (src):
 shim-15.8-150300.4.20.2
Basesystem Module 15-SP5 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src):
 shim-15.8-150300.4.20.2
SUSE Manager Proxy 4.3 (src):
 shim-15.8-150300.4.20.2
SUSE Manager Retail Branch Server 4.3 (src):
 shim-15.8-150300.4.20.2
SUSE Manager Server 4.3 (src):
 shim-15.8-150300.4.20.2
SUSE Enterprise Storage 7.1 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Micro 5.1 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Micro 5.2 (src):
 shim-15.8-150300.4.20.2
SUSE Linux Enterprise Micro for Rancher 5.2 (src):
 shim-15.8-150300.4.20.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Joe Fruchey 2024-04-22 13:22:25 UTC
Thank you for the update! 

My customer is on SLES_SAP 15 SP2. Can it be published there as well?
Comment 24 Marcus Meissner 2024-04-22 13:28:23 UTC
We will work on 15-SP2, 12-SP5 shim updates now.
Comment 27 Maintenance Automation 2024-04-29 12:30:03 UTC
SUSE-SU-2024:1462-1: An update that solves seven vulnerabilities, contains one feature and has five security fixes can now be installed.

Category: security (important)
Bug References: 1198101, 1205588, 1205855, 1210382, 1213945, 1215098, 1215099, 1215100, 1215101, 1215102, 1215103, 1219460
CVE References: CVE-2022-28737, CVE-2023-40546, CVE-2023-40547, CVE-2023-40548, CVE-2023-40549, CVE-2023-40550, CVE-2023-40551
Jira References: PED-922
Maintenance Incident: [SUSE:Maintenance:33581](https://smelt.suse.de/incident/33581/)
Sources used:
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src):
 shim-15.8-25.30.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src):
 shim-15.8-25.30.1
SUSE Linux Enterprise Server 12 SP5 (src):
 shim-15.8-25.30.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 28 Maintenance Automation 2024-04-29 12:30:09 UTC
SUSE-SU-2024:1461-1: An update that solves seven vulnerabilities, contains one feature and has five security fixes can now be installed.

Category: security (important)
Bug References: 1198101, 1205588, 1205855, 1210382, 1213945, 1215098, 1215099, 1215100, 1215101, 1215102, 1215103, 1219460
CVE References: CVE-2022-28737, CVE-2023-40546, CVE-2023-40547, CVE-2023-40548, CVE-2023-40549, CVE-2023-40550, CVE-2023-40551
Jira References: PED-922
Maintenance Incident: [SUSE:Maintenance:33579](https://smelt.suse.de/incident/33579/)
Sources used:
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src):
 shim-15.8-150100.3.38.1
SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src):
 shim-15.8-150100.3.38.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src):
 shim-15.8-150100.3.38.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.