Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: d6f41c4ff25bd277e9e67b9c9fea0172763aa367
      
https://github.com/tianocore/edk2/commit/d6f41c4ff25bd277e9e67b9c9fea0172763aa367
  Author: Kun Qin <[email protected]>
  Date:   2026-03-10 (Tue, 10 Mar 2026)

  Changed paths:
    M CryptoPkg/Library/BaseCryptLib/Pk/CryptX509.c

  Log Message:
  -----------
  CryptoPkg: BaseCryptLib: Reject empty X.509 cert when retrieving public key

Explicitly reject zero-length X.509 certificate buffers when retrieving a
public key. For this invalid case, the input context pointer is set to
NULL as a defensive measure.

Signed-off-by: Kun Qin <[email protected]>


  Commit: b980aa07196a5534581b16563cd78cfc67a74074
      
https://github.com/tianocore/edk2/commit/b980aa07196a5534581b16563cd78cfc67a74074
  Author: Kun Qin <[email protected]>
  Date:   2026-03-10 (Tue, 10 Mar 2026)

  Changed paths:
    M SecurityPkg/Library/AuthVariableLib/AuthService.c

  Log Message:
  -----------
  SecurityPkg: AuthVariableLib: Handle empty signature lists

The current implementation fails to set authenticated variables when the
signature list is empty. This can legitimately occur for dbx when no
signatures are revoked after a certificate rotation.

Update the logic to explicitly handle empty signature lists, avoiding an
implicit dependency on the variable being absent from variable storage.

Signed-off-by: Kun Qin <[email protected]>


Compare: https://github.com/tianocore/edk2/compare/e60688f7643d...b980aa07196a

To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to