[edk2-devel] [edk2-wiki][patch] Move feature BootGuard TOCTOU vulnerability to next edk2 stable tag

Liming Gao posted 1 patch 4 years, 5 months ago
Failed in applying to current master (apply log)
EDK-II-Release-Planning.md | 1 -
1 file changed, 1 deletion(-)
[edk2-devel] [edk2-wiki][patch] Move feature BootGuard TOCTOU vulnerability to next edk2 stable tag
Posted by Liming Gao 4 years, 5 months ago
This feature doesn't catch 201911 stable tag.
Plan to defer this feature to next stable tag.

Signed-off-by: Liming Gao <liming.gao@intel.com>
Cc: Michael Kubacki <michael.a.kubacki@intel.com>
---
 EDK-II-Release-Planning.md | 1 -
 1 file changed, 1 deletion(-)

diff --git a/EDK-II-Release-Planning.md b/EDK-II-Release-Planning.md
index 704e956..dabda3c 100644
--- a/EDK-II-Release-Planning.md
+++ b/EDK-II-Release-Planning.md
@@ -22,7 +22,6 @@
 * [Allow PCDs to be used in conditional statements if not referenced in an INF](https://bugzilla.tianocore.org/show_bug.cgi?id=2270)
 * [Add Support Laml and Lasa for TPM2 ACPI](https://bugzilla.tianocore.org/show_bug.cgi?id=978)
 * [Add PCI Device Security Support](https://bugzilla.tianocore.org/show_bug.cgi?id=2303)
-* [BootGuard TOCTOU vulnerability (CVE-2019-11098)](https://bugzilla.tianocore.org/show_bug.cgi?id=1614)
 * [Invalid server certificate accepted in HTTPS Boot (CVE-2019-14553)](https://bugzilla.tianocore.org/show_bug.cgi?id=960)
 * [MdeModulePkg: Enable/Disable S3BootScript dynamically](https://bugzilla.tianocore.org/show_bug.cgi?id=2212)
 * [Enable Phase 1 of Continuous Integration (CI) on the edk2 repository](https://bugzilla.tianocore.org/show_bug.cgi?id=2315)
-- 
2.13.0.windows.1


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.

View/Reply Online (#51003): https://edk2.groups.io/g/devel/message/51003
Mute This Topic: https://groups.io/mt/61064696/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub  [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-

Re: [edk2-devel] [edk2-wiki][patch] Move feature BootGuard TOCTOU vulnerability to next edk2 stable tag
Posted by Kubacki, Michael A 4 years, 5 months ago
Reviewed-by: Michael Kubacki <michael.a.kubacki@intel.com>

> -----Original Message-----
> From: devel@edk2.groups.io <devel@edk2.groups.io> On Behalf Of Liming
> Gao
> Sent: Wednesday, November 20, 2019 11:41 PM
> To: devel@edk2.groups.io
> Cc: Kubacki, Michael A <michael.a.kubacki@intel.com>
> Subject: [edk2-devel] [edk2-wiki][patch] Move feature BootGuard TOCTOU
> vulnerability to next edk2 stable tag
> 
> This feature doesn't catch 201911 stable tag.
> Plan to defer this feature to next stable tag.
> 
> Signed-off-by: Liming Gao <liming.gao@intel.com>
> Cc: Michael Kubacki <michael.a.kubacki@intel.com>
> ---
>  EDK-II-Release-Planning.md | 1 -
>  1 file changed, 1 deletion(-)
> 
> diff --git a/EDK-II-Release-Planning.md b/EDK-II-Release-Planning.md index
> 704e956..dabda3c 100644
> --- a/EDK-II-Release-Planning.md
> +++ b/EDK-II-Release-Planning.md
> @@ -22,7 +22,6 @@
>  * [Allow PCDs to be used in conditional statements if not referenced in an
> INF](https://bugzilla.tianocore.org/show_bug.cgi?id=2270)
>  * [Add Support Laml and Lasa for TPM2
> ACPI](https://bugzilla.tianocore.org/show_bug.cgi?id=978)
>  * [Add PCI Device Security
> Support](https://bugzilla.tianocore.org/show_bug.cgi?id=2303)
> -* [BootGuard TOCTOU vulnerability (CVE-2019-
> 11098)](https://bugzilla.tianocore.org/show_bug.cgi?id=1614)
>  * [Invalid server certificate accepted in HTTPS Boot (CVE-2019-
> 14553)](https://bugzilla.tianocore.org/show_bug.cgi?id=960)
>  * [MdeModulePkg: Enable/Disable S3BootScript
> dynamically](https://bugzilla.tianocore.org/show_bug.cgi?id=2212)
>  * [Enable Phase 1 of Continuous Integration (CI) on the edk2
> repository](https://bugzilla.tianocore.org/show_bug.cgi?id=2315)
> --
> 2.13.0.windows.1
> 
> 
> 


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.

View/Reply Online (#51260): https://edk2.groups.io/g/devel/message/51260
Mute This Topic: https://groups.io/mt/61064696/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub  [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-