{"id":"AZL-95634","summary":"CVE-2026-19411 affecting package shim-unsigned-aarch64 16.1-2","details":"A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.","modified":"2026-09-20T05:33:47Z","published":"2026-08-10T21:17:23Z","upstream":["CVE-2026-19411"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19411"}],"affected":[{"package":{"name":"shim-unsigned-aarch64","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/shim-unsigned-aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"16.1-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-95634.json"}}],"schema_version":"1.9.0"}