This fixes several issues, most notably BZ#1955416 and CVE-2022-28737. Please test.
Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:
sudo dnf upgrade --refresh --advisory=FEDORA-2022-98830efc68
Please login to add feedback.
This update has been submitted for testing by pjones.
This update's test gating status has been changed to 'ignored'.
pjones edited this update.
pjones edited this update.
New build(s):
Karma has been reset.
This update has been submitted for testing by pjones.
rharwood edited this update.
Boots my SB vm.
This update has been pushed to testing.
This update can be pushed to stable now if the maintainer wishes
Fixed firmware updates with Secure Boot enabled, tested on the Lenovo T14s. Thanks!
This update has been submitted for stable by bodhi.
Worked with secure boot enabled on my Thinkpad X1gen9 for Fedora boot and applying UEFI Capsule Updates
This update has been pushed to stable.
Just out of curiosity, this update is for F35 only, right? No other branches need it?
pjones spoke to that in https://bugzilla.redhat.com/show_bug.cgi?id=1955416#c88:
Since this update is now stable, I imagine it will shortly be okay to do so if it's not already.
Cool, thanks for the tip. Works on a couple of F36 machines here. A T450s (secure boot) and a noname PC.
This should go out in F36 and rawhide on the next updates push.
This shim has a regression, it does not allow to work with third-party enrolled certificates or binary file hashes. It always shows security violation screen, regardless what is enrolled into moklist using mokmanager or efitools keytool.
This does not affect fedora-signed binaries like GRUB and possibly other bootloaders, but this functionality worked on a previous versions.
@valdikss it really needs its own bug report, have you confirmed the problem definitely goes away if you replace/downgrade only /EFI/fedora/shim.efi and /EFI/fedora/shimx64.efi with the previous shim? If you can reproduce, you should give this update thumbs down karma. Thanks.
@chrismurphy, sorry, my bad, this regression was introduced in the previous version, not in this. https://bugzilla.redhat.com/show_bug.cgi?id=2099380