shim-15.6~rc2

- What's Changed
* SBAT Policy latest should be a one-shot by @jsetje in https://github.com/rhboot/shim/pull/481
* pe: Fix a buffer overflow when SizeOfRawData > VirtualSize by @chriscoulson
* pe: Perform image verification earlier when loading grub by @chriscoulson
* Update advertised sbat generation number for shim by @jsetje
* Update SBAT generation requirements for 05/24/22 by @jsetje
* Also avoid CVE-2022-28737 in verify_image() by @vathpela

- Full Changelog**: https://github.com/rhboot/shim/compare/15.6-rc1..15.6-rc2