Javier Martinez Canillas d298b41f90 mmap: Don't register cutmem and badram commands when lockdown is enforced
The cutmem and badram commands can be used to remove EFI memory regions
and potentially disable the UEFI Secure Boot. Prevent the commands to be
registered if the GRUB is locked down.

Fixes: CVE-2020-27779

Reported-by: Teddy Reed <teddy.reed@gmail.com>
Signed-off-by: Javier Martinez Canillas <javierm@redhat.com>
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
2021-03-02 15:54:15 +01:00
..
2013-12-18 05:28:05 +01:00
2013-10-27 20:34:24 +01:00
2021-03-02 15:54:15 +01:00
2012-05-04 00:30:15 +02:00
2012-02-28 12:58:57 +01:00
2009-06-10 21:04:23 +00:00