shim 15.8-1 source package in Debian

Changelog

shim (15.8-1) unstable; urgency=medium

  [ Steve McIntyre ]
  * Cope with changes in pesign packaging. Closes: #1057606
  * New upstream release fixing more bugs. Closes: #1061519, #1064220
    + CVE-2023-40546 mok: fix LogError() invocation (Closes: #1054210)
    + CVE-2023-40547 - avoid incorrectly trusting HTTP headers
    + CVE-2023-40548 Fix integer overflow on SBAT section size on
      32-bit system
    + CVE-2023-40549 Authenticode: verify that the signature header is
      in bounds.
    + CVE-2023-40550 pe: Fix an out-of-bound read in
      verify_buffer_sbat()
    + CVE-2023-40551: pe-relocate: Fix bounds check for MZ binaries
  * Remove all our previous patches, no longer needed:
    + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now
      upstream)
    + Enable-NX.patch (we don't want NX just yet until the whole boot
      stack is NX-capable)
    + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT
      is 4)
  * Cherry-pick 2 new patches from upstream for grub revocations:
    + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch
    + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch
  * NOTE: Stop building for i386
    + Debian kernels are no longer signed for i386, it's time to stop
      supporting i386 SB.
  * Log if the build is nx-compatible or not
  * Force shim to use the latest revocations by default to block some
    older grub / peimage issues. This is:
    "shim,4\ngrub,4\ngrub.peimage,2\n"
  * Install a copy of the Debian CA certificate into /usr/share/shim.
    Closes: #1069054
  * Clean up better after build. Closes: #1046268

  [ Bastien Roucariès ]
  * Port autopkgtest from ubuntu
  * Import MR-12: "shim-unsigned:amd64 cannot be installed alongside
    shim-unsigned:i386", thanks to adrian15 adrian15 (Closes: #936009).
  * Fix debian/watch and check signature (Closes: #1043485)

 -- Steve McIntyre <email address hidden>  Sat, 04 May 2024 23:29:52 +0100

Upload details

Uploaded by:
Debian UEFI Maintainers
Uploaded to:
Sid
Original maintainer:
Debian UEFI Maintainers
Architectures:
amd64 arm64
Section:
misc
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section
Sid release main misc

Builds

Downloads

File Size SHA-256 Checksum
shim_15.8-1.dsc 2.4 KiB 65ca82c131a66362a0bb222497eebbca5d64ba9efd44738d7889eb0500b5e4fa
shim_15.8.orig.tar.bz2 2.2 MiB a79f0a9b89f3681ab384865b1a46ab3f79d88b11b4ca59aa040ab03fffae80a9
shim_15.8-1.debian.tar.xz 57.9 KiB fad222c56f31a20b65753f16c66e270082295a2cccf2909686a980f19be665de

No changes file available.

Binary packages built by this source