rhboot / shim

UEFI shim loader
Other
816 stars 284 forks source link

sbat: Also bump latest for grub,4 (and to todays date) #653

Closed julian-klode closed 2 months ago

julian-klode commented 2 months ago
Back in January we decided to bump the SBAT level for the shim
CVE without bumping the grub level for the previous NTFS issues
- CVE-2023-4692 CVE-2023-4693 - as not every vendor was signing
the ntfs module.

Catch up on this revocation to ensure it doesn't get lost. Doing
so also allows us to remove the grub.debian,4 revocation as this
happened before grub,4 and hence is obsolete.

Also bump the date of the sbat variable to today's. Don't copy
the April 5 one to a previous selection, as it wasn't shipped
to anyone.