index
:
efi-boot-shim.git
bookworm/updates
bullseye/updates
buster/updates
master
upstream
vyos/current
(mirror of https://github.com/vyos/efi-boot-shim.git)
summary
refs
log
tree
commit
diff
log msg
author
committer
range
Age
Commit message (
Expand
)
Author
2024-01-22
Bump version to 15.8
15.8
Peter Jones
2024-01-22
gitmodules: use shim-15.8 for gnu-efi branch
Peter Jones
2024-01-22
Try to load revocations.efi even if directory read fails
Jan Setje-Eilers
2024-01-22
netboot read_image() should not hardcode DEFAULT_LOADER
Jan Setje-Eilers
2024-01-22
Build time selectable automatic SBATLevel revocations
Jan Setje-Eilers
2024-01-22
Rename "previous" revocations to "automatic"
Jan Setje-Eilers
2024-01-22
Suppress "Failed to open <..>\revocations.efi" when file does not exist
Jan Setje-Eilers
2024-01-22
pe-relocate: Avoid __builtin_add_overflow() on GCC < 5
Peter Jones
2024-01-22
post-process-pe: Don't set the NX_COMPAT flag by default after all.
Peter Jones
2024-01-22
Fix some minor ia32 build issues.
Peter Jones
2024-01-17
Updated Revocations for January 2024 CVEs
Jan Setje-Eilers
2023-12-05
Print errors when setting/clearing memory attrs
Peter Jones
2023-12-05
CVE-2023-40547 - avoid incorrectly trusting HTTP headers
Peter Jones
2023-12-05
sbat revocations: check the full section name
Peter Jones
2023-12-05
Print message when refusing to apply SbatLevel
Jan Setje-Eilers
2023-12-05
shim should not self revoke
Jan Setje-Eilers
2023-12-05
BS Variables for bootmgr revocations
Jan Setje-Eilers
2023-12-05
Always clear SbatLevel when Secure Boot is disabled
Jan Setje-Eilers
2023-12-05
Allow SbatLevel data from external binary
Jan Setje-Eilers
2023-12-05
Further mitigations against CVE-2023-40546 as a class
Peter Jones
2023-12-05
CVE-2023-40548 Fix integer overflow on SBAT section size on 32-bit system
Peter Jones
2023-12-05
CVE-2023-40549 Authenticode: verify that the signature header is in bounds.
Peter Jones
2023-12-05
pe-relocate: Ensure nothing else implements CVE-2023-40550
Peter Jones
2023-12-05
CVE-2023-40550 pe: Fix an out-of-bound read in verify_buffer_sbat()
Peter Jones
2023-12-05
pe-relocate: make read_header() use checked arithmetic operations.
Peter Jones
2023-12-05
CVE-2023-40551: pe-relocate: Fix bounds check for MZ binaries
Peter Jones
2023-12-05
pe-relocate: Add a fuzzer for read_header()
Peter Jones
2023-12-05
Add primitives for overflow-checked arithmetic operations.
Peter Jones
2023-10-19
CVE-2023-40546 mok: fix LogError() invocation
Peter Jones
2023-08-25
compile_commands.json: remove stuff clang doesn't like
Peter Jones
2023-08-25
Make some of the static analysis tools a little easier to run
Peter Jones
2023-07-19
mok: Avoid underflow in maximum variable size calculation
Alper Nebi Yasak
2023-07-19
Correctly free memory allocated in handle_image()
Dennis Tseng
2023-07-19
Work around ImageAddress() usage mistake
Dennis Tseng
2023-06-29
Add libFuzzer support to the .sbat parser.
Peter Jones
2023-06-29
Fix a 1-byte memory leak in .sbat parsing.
Peter Jones
2023-06-29
Add libFuzzer support for csv.c
Peter Jones
2023-06-27
Verify signature before verifying sbat levels
Jan Setje-Eilers
2023-06-23
Test (and fix) ImageAddress()
Peter Jones
2023-06-23
Split pe.c up even more.
Peter Jones
2023-06-23
Remove CentOS 7 test builds.
Peter Jones
2023-06-23
test: Make our fake dprintf be a statement.
Peter Jones
2023-06-23
Add gnu-stack notes
Peter Jones
2023-06-23
Add a make rule for compile_commands.json
Peter Jones
2023-06-21
Use -Wno-unused-but-set-variable for Cryptlib and OpenSSL
Peter Jones
2023-06-21
Add SbatLevel_Variable.txt to document the various revocations
Jan Setje-Eilers
2023-06-21
Change type of fallback_verbose_wait from int to unsigned long
Kamil Aronowski
2023-06-21
Rename 'msecs' to 'usecs' to avoid potential confusion
Kamil Aronowski
2023-06-21
Skip testing msleep()
Kamil Aronowski
2023-06-21
pe: only process RelocDir->Size of reloc section
Mike Beaton
[next]