(address . bug-guix@gnu.org)
As outlined by
we have a new wave of GRUB security vulnerabilities around SecureBoot.
There is no new upstream release so patching this appears to be some
kind of sport.
Debian has patched it in this commit:
I see also there's a new concept of SBAT section to ease administrative
efforts around certificate revocation when signed binaries such as some
GRUB2 things become vulnerable (and we don't want them to verify
successfully anymore).
This looks like a sizeable upgrade to a sensitive part of GNU Guix, so
we have to test carefully.
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEFIvLi9gL+xax3g6RRaix6GvNEKYFAmBQZ38ACgkQRaix6GvN
EKZD9xAAphY8xFLTczFCZLKoZw4UkFsvMLHdiarD/RoDWFzATRHJqB/vN9chAXfk
Ou56B6qOKtGwevwSlvCNXx9fSQS90Ae3h5HqyqZDgO5I3AVQPcXEYeylgngV18NG
exh0Vzmyd+Ue8mBpFKcLTuph3C5WffJXgFGpGZBcoMlSLOMVGAUKxY8uQLCAoaN1
CsBuIKFV+5kAbK+H480UVanpudMFuzPadWHXlwRbV/uPMDQL5FuFlRQ+ZDbKZQjJ
FdnoR0bKFRfYHofqf/EflEX3V0kYkUI/Kk0uzoEtGfiUVE/iS8r0s2sCvPII7Her
374GCS06zzIguMPtqiO7ikg0oJtJ2I+C9WTfYvZe3bKTRXUXdYUPuTwqQVd9uyuQ
QP4w5wwTCvidJ7iYZoA5Vk27Cs6JnOsds8PG7b4nQhSluATiVckOGz50H1G8SOlE
gnVEuxT6NIqYYtYOLFJfmNTIU4hnKKwSun3DMxr5UgL54M/MnoWrCCPiFO6R8GMR
bICsP59N9EqKGaoYtAxjOdKIQnBT2NBnBcmsGVhakDnS34OX5dd54w2sFjZkSgkK
Rx20A4bg1ODwRJkrICRuhDagg8P47SiovFxQzjiXA3Va1we06yCxpzUXsIK9SyH8
WhEhxgAoh+pi37K4fTj76Tj+NODwYICuTwWx5A0Me5/DrPqkltk=
=f/yr
-----END PGP SIGNATURE-----