shim-signed 1.37~18.04.13 source package in Ubuntu
Changelog
shim-signed (1.37~18.04.13) bionic; urgency=medium [ dann frazier ] * Fix arm64 issues due to hardcoding "x64" as the EFI architecture. (LP: #2004208) * is-not-revoked: Support vmlinux.gz files as used on arm64. (LP: #2004201) shim-signed (1.37~18.04.12) bionic; urgency=medium * New upstream version 15.7 (LP: #1996503) - SBAT level: shim,3 - SBAT policy bumped to for grub,2 in previous and grub,3 in latest: SBAT policy: latest="shim,2\ngrub,3\n" previous="grub,2\n" * SECURITY FIX: Buffer overflow when loading crafted EFI images. - CVE-2022-28737 * debian/control: Depend on new grub versions (1.191 on lunar+, 1.187.2 elsewhere) * Break fwupd-signed signed with old keys * Check for revoked fb,mm binaries in build, grubs, fwupd in autopkgtest * Install both previous and latest shim as alternatives. On secure boot systems, if the current kernel or any newer one is revoked, the previous shim will continue to be used until current kernel and all newer ones are signed with a non-revoked key. -- Julian Andres Klode <email address hidden> Tue, 31 Jan 2023 12:57:37 +0100
Upload details
- Uploaded by:
- Julian Andres Klode
- Uploaded to:
- Bionic
- Original maintainer:
- Steve Langasek
- Architectures:
- amd64 arm64
- Section:
- utils
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section | |
---|---|---|---|---|
Bionic | updates | main | utils |
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
shim-signed_1.37~18.04.13.tar.xz | 903.8 KiB | eccc991ad4abaa0a32e52c5b8ff61450be5f024e0cc5e5fb26cd0122b7c554ff |
shim-signed_1.37~18.04.13.dsc | 1.8 KiB | 319b8384aa004f9aea5a61acf3161125b5b94109b4bd0bf92af3ad36cb70b0c2 |
Available diffs
- diff from 1.37~18.04.11 (in Ubuntu) to 1.37~18.04.13 (4.0 KiB)
- diff from 1.37~18.04.12 to 1.37~18.04.13 (1.6 KiB)
- diff from 1.41 to 1.37~18.04.13 (12.9 KiB)
Binary packages built by this source
- shim-signed: Secure Boot chain-loading bootloader (Microsoft-signed binary)
This package provides a minimalist boot loader which allows verifying
signatures of other UEFI binaries against either the Secure Boot DB/DBX or
against a built-in signature database. Its purpose is to allow a small,
infrequently-changing binary to be signed by the UEFI CA, while allowing
an OS distributor to revision their main bootloader independently of the CA.
.
This package contains the version of the bootloader binary signed by the
Microsoft UEFI CA.