Comment 11 for bug 2040137

Revision history for this message
dann frazier (dannf) wrote : Re: [Bug 2040137] Re: exposing the EFI shell in Secure Boot mode can lead to security bypass

On Wed, Dec 6, 2023 at 1:36 AM Mate Kukri <email address hidden> wrote:
>
> A fairly simple and non-invasive fix I could PoC would be to patch EDK2
> to only allow launching the Shell if SecureBootEnabled==0 ||
> SecureBoot==0 || SetupMode==1.
>
> That way key enrollment could stay identical for now, users with SB
> disabled would still have the shell available, and theoretically
> (fingers crossed) we'd get away with a small patch.

Yes, I agree that would be ideal. Is there a channel open with
upstream on this matter where we could discuss such a patch? If not,
shall we open a security bug in their bugzilla?
  https://github.com/tianocore/tianocore.github.io/wiki/Reporting-Security-Issues