CVE-2026-19411

Publication date 13 August 2026

Last updated 13 August 2026


Ubuntu priority

Cvss 3 Severity Score

3.9 · Low

Score breakdown

Description

A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.

Read the notes from the security team

Status

Package Ubuntu Release Status
secureboot-db 26.04 LTS resolute
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial Ignored install media keys will never be revoked
14.04 LTS trusty Ignored install media keys will never be revoked
shim-signed 26.04 LTS resolute
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial Ignored install media keys will never be revoked
14.04 LTS trusty Ignored install media keys will never be revoked
shim 26.04 LTS resolute
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial Ignored install media keys will never be revoked
14.04 LTS trusty Ignored install media keys will never be revoked

Notes


eslerm

secureboot-db should only ever be updated after shim secureboot-db is not updated on ESM releases as doing so would revoke install media keys Note that key revocation is required to protect against evil housekeeper attacks (such as BlackLotus)

Severity score breakdown

CVSS version: CVSS v3.0

Base score 3.9 · Low

Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L


Access our resources on patching vulnerabilities