CVE-2026-19411
Publication date 13 August 2026
Last updated 13 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| secureboot-db | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial | Ignored install media keys will never be revoked | |
| 14.04 LTS trusty | Ignored install media keys will never be revoked | |
| shim-signed | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial | Ignored install media keys will never be revoked | |
| 14.04 LTS trusty | Ignored install media keys will never be revoked | |
| shim | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial | Ignored install media keys will never be revoked | |
| 14.04 LTS trusty | Ignored install media keys will never be revoked |
Notes
eslerm
secureboot-db should only ever be updated after shim secureboot-db is not updated on ESM releases as doing so would revoke install media keys Note that key revocation is required to protect against evil housekeeper attacks (such as BlackLotus)
Severity score breakdown
CVSS version: CVSS v3.0
Base score
3.9 · Low
Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:L