1. 24 Jul, 2018 1 commit
  2. 13 Sep, 2017 1 commit
  3. 04 Aug, 2017 1 commit
  4. 22 Sep, 2016 1 commit
  5. 06 May, 2015 1 commit
  6. 08 Oct, 2014 1 commit
    • Steve Langasek's avatar
      * SECURITY UPDATE: heap overflow and out-of-bounds read access when · 3586772f
      Steve Langasek authored
        parsing DHCPv6 information
        - debian/patches/CVE-2014-3675.patch: apply proper bounds checking
          when parsing data provided in DHCPv6 packets.
        - CVE-2014-3675
        - CVE-2014-3676
      * SECURITY UPDATE: memory corruption when processing user-provided key
        lists
        - debian/patches/CVE-2014-3677.patch: detect malformed machine owner
          key (MOK) lists and ignore them, avoiding possible memory corruption.
        - CVE-2014-3677
      3586772f
  7. 06 Oct, 2014 1 commit
  8. 02 Oct, 2014 2 commits
  9. 12 Aug, 2014 1 commit
    • Ard Biesheuvel's avatar
      Factor out x86-isms and add cross compile support · f7a18215
      Ard Biesheuvel authored
      This patch cleans up and refactors the Makefiles to better allow new
      architectures to be added:
      - remove unused Makefile definitions
      - import Makefile definitions from top level rather than redefining
      - move x86 specific CFLAGS to inside ifeq() blocks
      - remove x86 inline asm
      - allow $(FORMAT) to be overridden: this is necessary as there exists no
        EFI or PE/COFF aware objcopy for ARM
      Signed-off-by: 's avatarArd Biesheuvel <ard.biesheuvel@linaro.org>
      f7a18215
  10. 25 Jun, 2014 1 commit
    • Gary Ching-Pang Lin's avatar
      Fetch the netboot image from the same device · da49ac6d
      Gary Ching-Pang Lin authored
      The previous strategy is to locate the first available PXE_BASE_CODE
      protocol and to fetch the second stage image from it, and this may
      cause shim to fetch the wrong second stage image, i.e. grub.efi.
      
      Consider the machine with the following boot order:
      1. PXE Boot
      2. Hard Drive
      
      Assume that the EFI image, e.g. bootx64.efi, in the PXE server is
      broken, then "PXE Boot" will fail and fallback to "Hard Drive". While
      shim.efi in "Hard Drive" is loaded, it will find the PXE protocol is
      available and fetch grub.efi from the PXE server, not grub.efi in the
      disk.
      
      This commit checks the DeviceHandle from Loaded Image. If the device
      supports PXE, then shim fetches grub.efi with the PXE protocol. Otherwise,
      shim loads grub.efi from the disk.
      Signed-off-by: 's avatarGary Ching-Pang Lin <glin@suse.com>
      da49ac6d
  11. 21 Nov, 2013 2 commits
  12. 02 Oct, 2013 1 commit
  13. 26 Sep, 2013 2 commits
  14. 24 Sep, 2013 7 commits
  15. 23 Sep, 2013 1 commit
  16. 20 Sep, 2013 3 commits
  17. 31 May, 2013 1 commit
  18. 01 Nov, 2012 1 commit
  19. 13 Oct, 2012 1 commit