A vulnerability categorized as problematic has been discovered in Shim. The affected element is the function is_removable_media_path of the file shim/dp.c. The manipulation results in null pointer dereference.

This vulnerability is reported as CVE-2026-19411. The attack requires a local approach. No exploit exists.