Skip to content

NX_COMPAT shims should force NX_REQUIRE in mok_policy. #757

@kukrimate

Description

@kukrimate

It is currently possible to build a shim with an insecure configuration where NX_COMPAT flag in DllCharacteristics is set but mok_policy does not have NX_REQUIRE flag set.

This should be prevented because such a shim can be booted on NX enforcing firmware and can be used to chainload non-NX binaries and thus becomes an NX bypass tool.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions