CVE-2014-3676: Red Hat Shim

High severity, CVSS 7.5. EPSS: 5.2% chance of exploitation in the next 30 days.

Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."

Affected products

  • Red Hat Shim: from 0.3, before 0.8 (fixed in 0.8)

Published 2014-10-22. Last modified 2026-06-17.