Database/Firmware, BMC & network fabric
GRUB2 (shim_lock verifier): The shim_lock verifier let non-kernel files through, so an attacker could get unsigned
Impact
The shim_lock verifier let non-kernel files through, so an attacker could get unsigned content loaded into the boot path while Secure Boot enforcement appeared intact. It defeats the exact control operators rely on to promise a clean handoff between bare-metal tenants.
Who can reach it
Local, with the ability to place a file GRUB will load.
What to do
grub2 package update + reboot. This is one where the dbx revocation genuinely matters - without it the old signed GRUB remains a usable bypass tool that an attacker can simply drop onto a patched node.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.