Secure boot via pxeboot fails with updated grub2
Bug #1927730 reported by
Don Penney
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
StarlingX |
Fix Released
|
High
|
Don Penney |
Bug Description
Brief Description
-----------------
Secure boot via pxeboot fails due to CVE update in grub2 (CVE-2020-15705). The pxeboot install from the active controller for secure boot is currently using grubx64.efi directly, without using a shim.efi, which was bypassing the secure boot validation with the earlier grub2. With the recent update, the pxeboot must use shim.efi, or the kernel is rejected.
Severity
--------
Critical
Branch/Pull Time/Commit
-------
CVE Update was merged into starlingx/master Feb 18, 2021:
https:/
Test Activity
-------------
Regression Testing
CVE References
tags: | added: stx.distro.other |
Changed in starlingx: | |
importance: | Undecided → Critical |
assignee: | nobody → Don Penney (dpenney) |
tags: |
added: in-r-stx50 removed: stx.cherrypickneeded |
To post a comment you must log in.
Fix proposed to branch: master /review. opendev. org/c/starlingx /metal/ +/790253
Review: https:/