Skip to content
Snippets Groups Projects
Commit 24e6d59a authored by Julian Andres Klode's avatar Julian Andres Klode
Browse files

kern/efi/sb: Reject non-kernel files in the shim_lock verifier


We must not allow other verifiers to pass things like the GRUB modules.
Instead of maintaining a blocklist, maintain an allowlist of things
that we do not care about.

This allowlist really should be made reusable, and shared by the
lockdown verifier, but this is the minimal patch addressing
security concerns where the TPM verifier was able to mark modules
as verified (or the OpenPGP verifier for that matter), when it
should not do so on shim-powered secure boot systems.

Fixes: CVE-2022-28735

Signed-off-by: default avatarJulian Andres Klode <julian.klode@canonical.com>
Reviewed-by: default avatarDaniel Kiper <daniel.kiper@oracle.com>
parent 19b4f19c
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment