-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 13 Feb 2024 18:22:25 -0700 Source: edk2 Binary: ovmf ovmf-ia32 qemu-efi qemu-efi-aarch64 qemu-efi-arm Architecture: all Version: 2020.11-2+deb11u2 Distribution: bullseye-security Urgency: medium Maintainer: all Build Daemon (x86-csail-02) Changed-By: dann frazier Description: ovmf - UEFI firmware for 64-bit x86 virtual machines ovmf-ia32 - UEFI firmware for 32-bit x86 virtual machines qemu-efi - transitional dummy package qemu-efi-aarch64 - UEFI firmware for 64-bit ARM virtual machines qemu-efi-arm - UEFI firmware for 32-bit ARM virtual machines Changes: edk2 (2020.11-2+deb11u2) bullseye-security; urgency=medium . * Disable the built-in Shell when SecureBoot is enabled, CVE-2023-48733. Thanks to Mate Kukri. LP: #2040137. - Backport support for GetSetupMode() and IsSecureBootEnabled(): + 0001-SecurityPkg-Create-SecureBootVariableLib.patch + 0002-ArmVirtPkg-add-SecureBootVariableLib-class-resolutio.patch + 0003-OvmfPkg-add-SecureBootVariableLib-class-resolution.patch + 0004-SecurityPkg-SecureBootVariableLib-Added-newly-suppor.patch + 0005-EmulatorPkg-add-SecureBootVariableLib-class-resoluti.patch - Disable the built-in Shell when SecureBoot is enabled: + Disable-the-Shell-when-SecureBoot-is-enabled.patch - d/tests: Drop the boot-to-shell tests for images w/ Secure Boot active. Checksums-Sha1: 7bb0ffaf71d76353c233c8d19404f3198d45148c 11601 edk2_2020.11-2+deb11u2_all-buildd.buildinfo 8437b2095c7d3a1c712bdfdcd7a35e644c8c8553 1450600 ovmf-ia32_2020.11-2+deb11u2_all.deb 9ee8155cf5de2c1e18c1b7c4161141077b17bdcc 7194056 ovmf_2020.11-2+deb11u2_all.deb c48baf09ad9fc15efb97522a1e2a380b56bbb017 2375004 qemu-efi-aarch64_2020.11-2+deb11u2_all.deb 88b4e4fa0f2118f72a3b54a9c2c992bb3cf2e00e 1211112 qemu-efi-arm_2020.11-2+deb11u2_all.deb f3e04d976a12abd48dfa84bdbf3269ada36d104c 15660 qemu-efi_2020.11-2+deb11u2_all.deb Checksums-Sha256: 56d8d092aa6da617cd2a6e45190fb49f829e2200adc763135daf178f3733f5d2 11601 edk2_2020.11-2+deb11u2_all-buildd.buildinfo ef4023ddf8cc77f1b0b0900161449f1fff8a27845307b0d6f9cd9f6f12d2678c 1450600 ovmf-ia32_2020.11-2+deb11u2_all.deb 54a0814d2e2dab59af1143c8112fa4eda49d0d6f24581dd847fa78c4c7570563 7194056 ovmf_2020.11-2+deb11u2_all.deb 3b941fef407663f35026e7b40e0bca9c2efc83ad95c7c087634fc32b10fc6e99 2375004 qemu-efi-aarch64_2020.11-2+deb11u2_all.deb 671b9545797da58ca1a93dd7520e7f3e7899740eecea8619e81f39886677cd99 1211112 qemu-efi-arm_2020.11-2+deb11u2_all.deb 684db6ed3ab6076e411570b419f510d9058b83485d990d28c6842186925a005d 15660 qemu-efi_2020.11-2+deb11u2_all.deb Files: 3fba037e28bcb829dcd5dfc3f7a0116e 11601 misc optional edk2_2020.11-2+deb11u2_all-buildd.buildinfo 3cf7a712e75a57bd121a438647431080 1450600 misc optional ovmf-ia32_2020.11-2+deb11u2_all.deb 4157408f3205b99654aca060d62d28f2 7194056 misc optional ovmf_2020.11-2+deb11u2_all.deb d36d9c0ed2c4ae85a05c2766fb9c172d 2375004 misc optional qemu-efi-aarch64_2020.11-2+deb11u2_all.deb 14dbd3ea566e71699116b9102cdfe7d8 1211112 misc optional qemu-efi-arm_2020.11-2+deb11u2_all.deb bb510deb8324d7e1d1d115454ad2eccb 15660 misc optional qemu-efi_2020.11-2+deb11u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtzb3SVunlrB0F8t8ExOkVqF4GXMFAmXMLqgACgkQExOkVqF4 GXMJZA/+PIc11yrdmJFDDCK/2hosSCtGL//HfaCyL29KIxLGRACZQCFEHcAx8V4k lst5ENSkBq5Kbp+CuTu6fI1H/jIuIBpZa+2phbl9ke+cqNUU8CFAj0McErHPqlOG fig231r1Vr6rK/yVWkc/YS4Jwm6uv0gTZyJxjlXpMSfURUjS9W3f+1TQTeWuweKx q4u6Ag9nsc76QB7JHyOEkAwG0/9JaMr6wBZoYps2JXMZ4LcN3aD4en8U1st7A3kg A4LbN20wo0WvtJ6hZ1/SvQLWOKSHh7LHrXRsW/ndyqwpT7oiDpF36k54uJd6uQC2 mqpmdoe1Af/edcr9ZFkmObTji7//SEiCHVBKQ4Hh5Voi9NwTXTZS9sPVhYDtDqIr j79DK+sTkl17N+3mIzHxZsSZsdAw/cnBPoYQrEB98TDBHz1NLw+co6LYZ6cfoFq7 rhZCub59UNyD5JTdzyZmrHjf+yTYHIN+71MGv492Oqk1wdvcuZpIdaaVE5X5EK6P Sh6Bez9yVJSw3b+FF92J0ZJ12BJy9pLEMfioItwNKXbeEKHXmBI+Yae0ObaQLIAZ BKdetU+5OVwgYa6l5RfL49nzg6T/8U83K1qloz452VjNw3Rdakg+pushErenbe7W F6Waxc8V+u/2+B6df9L3cEO0XZiclXar7tEHF9n5LHKmWVqhkPw= =uUBV -----END PGP SIGNATURE-----