revocations.efi to deliver new sbat level requirements as well as updated bootmgr SkuSiPolicy#6
Open
jsetje wants to merge 5 commits intorhboot:mainfrom
Open
revocations.efi to deliver new sbat level requirements as well as updated bootmgr SkuSiPolicy#6jsetje wants to merge 5 commits intorhboot:mainfrom
jsetje wants to merge 5 commits intorhboot:mainfrom
Conversation
Author
|
While this works, I should admit that this is a bit of a strange binary and I wouldn't be surprised if there was a better way. I did run into the fact that the PE parsing in shim does not handle longer section names. Since that could be an attack surface, it probably makes sense to keep that code as simple as it can be. |
a8e9f89 to
03d0f36
Compare
Author
|
This contains a dangerous latest SkuSiPolicy version. While this is handy for testing, we may or may not want to ship this here. Comments are welcome. |
This covers delivering updates to SBAT_LEVEL without the need to create and sign a new shim Signed-off-by: Jan Setje-Eilers <Jan.SetjeEilers@oracle.com>
Signed-off-by: Jan Setje-Eilers <Jan.SetjeEilers@oracle.com>
This is also included in shim builtin latest revocation, but it revokes shim binaries impacted by: * CVE-2023-40547 * CVE-2023-40546 * CVE-2023-40548 * CVE-2023-40549 * CVE-2023-40550 * CVE-2023-40551 And also revokes GRUB binaries impacted by: * CVE-2023-4692 * CVE-2023-4693
When the term previous was introduced for revocations to be automatically applied there was a hope that everytime a new revocation was built into shim, the previous revocation could be applied automatically. Further experience has shown the real world to be more complex than that. The automatic payload will realistically contain a set of revocations governed by both the cadence at which a distro's customer base updates as well as the severity of the issue being revoked. This is not a functional change. Signed-off-by: Jan Setje-Eilers <Jan.SetjeEilers@oracle.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This covers delivering updates to SBAT_LEVEL without the need
to create and sign a new shim
Signed-off-by: Jan Setje-Eilers Jan.SetjeEilers@oracle.com