CVE-2026-19411

Public on 2026-08-10
Modified on 2026-08-12
Description
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.
Severity
Low severity
Low
See what this means
CVSS v3 Base Score
1.9
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core mokutil Not Affected
Amazon Linux 2023 mokutil Not Affected
Amazon Linux 2 - Core shim No Fix Planned

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L