rhboot / shim

UEFI shim loader
Other
857 stars 292 forks source link

Verify signature before verifying sbat levels #583

Closed jsetje closed 1 year ago

jsetje commented 1 year ago

Verifying the validity of a files signature can protect from an attacker creating a file that exploits a pontential issue in the sbat validation. If the singature is not checked first, an attacker can just create a file with a valid .sbat section and can still attack the signature valiation.