-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 05 May 2024 11:33:57 +0100 Source: shim Architecture: source Version: 15.8-1~deb11u1 Distribution: bullseye Urgency: medium Maintainer: Debian EFI team Changed-By: Steve McIntyre <93sam@debian.org> Closes: 1046268 1069054 Changes: shim (15.8-1~deb11u1) bullseye; urgency=medium . * New upstream release fixing more bugs * Remove all our previous patches, no longer needed: + Make-sbat_var.S-parse-right-with-buggy-gcc-binutils.patch (now upstream) + Enable-NX.patch (we don't want NX just yet until the whole boot stack is NX-capable) + block-grub-sbat3-debian.patch (not needed now upstream grub SBAT is 4) * Cherry-pick 2 new patches from upstream for grub revocations: + 0001-sbat-Add-grub.peimage-2-to-latest-CVE-2024-2312.patch + 0002-sbat-Also-bump-latest-for-grub-4-and-to-todays-date.patch * Log if the build is nx-compatible or not * Force shim to use the latest revocations by default to block some older grub / peimage issues. This is: "shim,4\ngrub,4\ngrub.peimage,2\n" * Install a copy of the Debian CA certificate into /usr/share/shim. Closes: #1069054 * Clean up better after build. Closes: #1046268 Checksums-Sha1: 14c630a27136f5200ae0de4052587952d0723d61 2347 shim_15.8-1~deb11u1.dsc cdec924ca437a4509dcb178396996ddf92c11183 2315201 shim_15.8.orig.tar.bz2 7c74dacc460c1c4c4043e7a0b3a21e46ff2ed5c2 34564 shim_15.8-1~deb11u1.debian.tar.xz ed4d901976e45e91ebc11e34b4b7a33512ea2879 6374 shim_15.8-1~deb11u1_source.buildinfo Checksums-Sha256: 45bceb4088694b9b0bf0654ddd6decfdbb74cf3093da0c9bd4b4f86b23525e89 2347 shim_15.8-1~deb11u1.dsc a79f0a9b89f3681ab384865b1a46ab3f79d88b11b4ca59aa040ab03fffae80a9 2315201 shim_15.8.orig.tar.bz2 0fe4199aa5b57ce6d9f8eb90be0a67465d279b088405b26e68a85026de17ce8f 34564 shim_15.8-1~deb11u1.debian.tar.xz 895e87658ea074fbfbce89acd469ea0ac393f19c6237f699c9cfa8852ce7fea8 6374 shim_15.8-1~deb11u1_source.buildinfo Files: 6ff7aa6a917691459e79e2fe8acddb45 2347 admin optional shim_15.8-1~deb11u1.dsc a9452c2e6fafe4e1b87ab2e1cac9ec00 2315201 admin optional shim_15.8.orig.tar.bz2 0fe2eb1872d29bb0645582144583b9b2 34564 admin optional shim_15.8-1~deb11u1.debian.tar.xz e3111ee798285b6d1574d666b711c4d8 6374 admin optional shim_15.8-1~deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJFBAEBCAAvFiEEzrtSMB1hfpEDkP4WWHl5VzRCaE4FAmY5DCQRHDkzc2FtQGRl Ymlhbi5vcmcACgkQWHl5VzRCaE5SIw//TJbMcxEOavC3jV6ghMo5pfCwFg8VwiNg Ktrmd9UBnTDoG8tcRbLimhL664+J8awLXXX8uhWeh90L8EG8Js4kPxui0K3fIcvL Th/L+eepa5C7VCegShh+/D9UlvofYIMRla/2Ny6u4MBSI4xllydSRL3GU8YMl2P1 Y/Hij7aHlDuYNlvwFtMXwYhoZKTr33W4h0iC9TIBeM9lkY2E/C2W0bfUZQF8SRCS rTJYuNSioEwUWz1+T/44na/HDZ8ixOT0B65GCTeOAuZ1n83mIjDdi5qXB9bCYVuq NqeUCF6yIOLliRdSx93kgY7VwzcqJKPiJocx73CD+oT4/fsqeO3nTu50hiSqTjIK YoAJLHEtE0HttGw3h54F1fXKOFx2bkCLRxRVtjCiFHrZWenwpAHBLPDxhR2k0xyR yGGYUzZ7Eowc0JKjfnwDhVv+ExFRtusAyYclp5OfolGbPtnHbo7GzsdPXOlfB2bM bysLe8hp8+HzdcANmko0GGElnBXxmtSZhcfkriJ1Fe3NQBs/A9S/oebTadsszocY IZUvp+ryu+yr99tqlov/aRaNYDv/PDjWhaw+q77dazcspiRYqFjIk/ZFfA+GASfd bdjB99/Swzy4KhMh2SW62tZr5wPm79jYVUCUDAY71fk3EgI2BFyZxCOmj2F0UD5g YhgcnRvNAdI= =wvyi -----END PGP SIGNATURE-----