pve-edk2-firmware/debian/patches/series
Fabian Grünbichler b82f91d3ec fix CVE-2023-48733: disable EFI shell in SB mode
since the shell allows circumvention of Secure Boot restrictions, for example
via raw memory access or execution of scripts on the ESP.

see Links in the patch for details.

Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
(cherry picked from commit 334229c409)
2024-02-15 14:36:17 +01:00

8 lines
294 B
Plaintext

no-stack-protector-all-archs.diff
brotlicompress-disable.diff
x64-baseline-abi.patch
Revert-ArmVirtPkg-make-EFI_LOADER_DATA-non-executabl.patch
0001-OvmfPkg-PlatformInitLib-limit-phys-bits-to-46.patch
CVE-2023-45229_45237.patch
CVE-2023-48733-Disable-the-Shell-when-SecureBoot-is-enabled.patch