-
Notifications
You must be signed in to change notification settings - Fork 3
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add some missing dbx files, and fix up some invalid dates
Many thanks to Youfu Zhang! Fixes #4
- Loading branch information
Showing
17 changed files
with
159 additions
and
12 deletions.
There are no files selected for viewing
File renamed without changes.
File renamed without changes.
Binary file not shown.
Binary file not shown.
File renamed without changes.
Binary file not shown.
Binary file not shown.
Binary file not shown.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,53 @@ | ||
<?xml version="1.0" encoding="UTF-8"?> | ||
<!-- Copyright 2022 Richard Hughes <[email protected]> --> | ||
<component type="firmware"> | ||
<id>org.linuxfoundation.dbx.x64.firmware</id> | ||
<name>Secure Boot dbx</name> | ||
<name_variant_suffix>x64</name_variant_suffix> | ||
<summary>UEFI Secure Boot Forbidden Signature Database</summary> | ||
<description> | ||
<p> | ||
Updating the UEFI dbx prevents starting EFI binaries with known security issues. | ||
</p> | ||
</description> | ||
<provides> | ||
<!-- Microsoft Corporation KEK CA 2011 - | ||
UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64 --> | ||
<firmware type="flashed">f8ba2887-9411-5c36-9cee-88995bb39731</firmware> | ||
</provides> | ||
<url type="homepage">https://uefi.org/revocationlistfile</url> | ||
<metadata_license>CC0-1.0</metadata_license> | ||
<project_license>proprietary</project_license> | ||
<developer_name>Microsoft Corporation</developer_name> | ||
<releases> | ||
<!-- for the version use `fwupdtool firmware-parse foo.bin efi-signature-list` --> | ||
<release urgency="high" version="183" date="2020-10-12"> | ||
<checksum filename="DBXUpdate-20201012.x64.bin" target="content"/> | ||
<description> | ||
<p> | ||
An insecure version of software from Cisco has been added to the list of forbidden | ||
signatures due to a discovered security problem. | ||
This updates the dbx to the latest release from Microsoft. | ||
</p> | ||
<p> | ||
Before installing the update, fwupd will check for any affected executables | ||
in the ESP and will refuse to update if it finds any boot binaries signed | ||
with any of the forbidden signatures. | ||
</p> | ||
</description> | ||
<issues> | ||
<issue type="cve">CVE-2023-28005</issue> | ||
</issues> | ||
</release> | ||
</releases> | ||
<requires> | ||
<id compare="ge" version="1.8.14">org.freedesktop.fwupd</id> | ||
</requires> | ||
<custom> | ||
<value key="LVFS::UpdateProtocol">org.uefi.dbx</value> | ||
<value key="LVFS::VersionFormat">number</value> | ||
</custom> | ||
<categories> | ||
<category>X-Configuration</category> | ||
</categories> | ||
</component> |
File renamed without changes.
File renamed without changes.
File renamed without changes.
File renamed without changes.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,53 @@ | ||
<?xml version="1.0" encoding="UTF-8"?> | ||
<!-- Copyright 2022 Richard Hughes <[email protected]> --> | ||
<component type="firmware"> | ||
<id>org.linuxfoundation.dbx.aa64.firmware</id> | ||
<name>Secure Boot dbx</name> | ||
<name_variant_suffix>aa64</name_variant_suffix> | ||
<summary>UEFI Secure Boot Forbidden Signature Database</summary> | ||
<description> | ||
<p> | ||
Updating the UEFI dbx prevents starting EFI binaries with known security issues. | ||
</p> | ||
</description> | ||
<provides> | ||
<!-- Microsoft Corporation KEK CA 2011 - | ||
UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_AA64 --> | ||
<firmware type="flashed">67d35028-ca5b-5834-834a-f97380381082</firmware> | ||
</provides> | ||
<url type="homepage">https://uefi.org/revocationlistfile</url> | ||
<metadata_license>CC0-1.0</metadata_license> | ||
<project_license>proprietary</project_license> | ||
<developer_name>Microsoft Corporation</developer_name> | ||
<releases> | ||
<!-- for the version use `fwupdtool firmware-parse foo.bin efi-signature-list` --> | ||
<release urgency="high" version="22" date="2022-09-07"> | ||
<checksum filename="DBXUpdate-20220907.aa64.bin" target="content"/> | ||
<description> | ||
<p> | ||
An insecure version of software from VMware has been added to the list of forbidden | ||
signatures due to a discovered security problem. | ||
This updates the dbx to the latest release from Microsoft. | ||
</p> | ||
<p> | ||
Before installing the update, fwupd will check for any affected executables | ||
in the ESP and will refuse to update if it finds any boot binaries signed | ||
with any of the forbidden signatures. | ||
</p> | ||
</description> | ||
<issues> | ||
<issue type="cve">CVE-2023-28005</issue> | ||
</issues> | ||
</release> | ||
</releases> | ||
<requires> | ||
<id compare="ge" version="1.8.14">org.freedesktop.fwupd</id> | ||
</requires> | ||
<custom> | ||
<value key="LVFS::UpdateProtocol">org.uefi.dbx</value> | ||
<value key="LVFS::VersionFormat">number</value> | ||
</custom> | ||
<categories> | ||
<category>X-Configuration</category> | ||
</categories> | ||
</component> |
Binary file not shown.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,53 @@ | ||
<?xml version="1.0" encoding="UTF-8"?> | ||
<!-- Copyright 2022 Richard Hughes <[email protected]> --> | ||
<component type="firmware"> | ||
<id>org.linuxfoundation.dbx.x64.firmware</id> | ||
<name>Secure Boot dbx</name> | ||
<name_variant_suffix>x64</name_variant_suffix> | ||
<summary>UEFI Secure Boot Forbidden Signature Database</summary> | ||
<description> | ||
<p> | ||
Updating the UEFI dbx prevents starting EFI binaries with known security issues. | ||
</p> | ||
</description> | ||
<provides> | ||
<!-- Microsoft Corporation KEK CA 2011 - | ||
UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64 --> | ||
<firmware type="flashed">f8ba2887-9411-5c36-9cee-88995bb39731</firmware> | ||
</provides> | ||
<url type="homepage">https://uefi.org/revocationlistfile</url> | ||
<metadata_license>CC0-1.0</metadata_license> | ||
<project_license>proprietary</project_license> | ||
<developer_name>Microsoft Corporation</developer_name> | ||
<releases> | ||
<!-- for the version use `fwupdtool firmware-parse foo.bin efi-signature-list` --> | ||
<release urgency="high" version="218" date="2022-09-07"> | ||
<checksum filename="DBXUpdate-20220907.x64.bin" target="content"/> | ||
<description> | ||
<p> | ||
An insecure version of software from VMware has been added to the list of forbidden | ||
signatures due to a discovered security problem. | ||
This updates the dbx to the latest release from Microsoft. | ||
</p> | ||
<p> | ||
Before installing the update, fwupd will check for any affected executables | ||
in the ESP and will refuse to update if it finds any boot binaries signed | ||
with any of the forbidden signatures. | ||
</p> | ||
</description> | ||
<issues> | ||
<issue type="cve">CVE-2023-28005</issue> | ||
</issues> | ||
</release> | ||
</releases> | ||
<requires> | ||
<id compare="ge" version="1.8.14">org.freedesktop.fwupd</id> | ||
</requires> | ||
<custom> | ||
<value key="LVFS::UpdateProtocol">org.uefi.dbx</value> | ||
<value key="LVFS::VersionFormat">number</value> | ||
</custom> | ||
<categories> | ||
<category>X-Configuration</category> | ||
</categories> | ||
</component> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters