It appears this should be fixed in linux-signed 4.15.0-20.21, but there was no bug reference in the changelog:
linux-signed (4.15.0-20.21) bionic; urgency=medium * Master version: 4.15.0-20.21 * Miscellaneous Ubuntu changes - fix permissions for installed signed kernel images ** Changed in: linux-signed (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Kernel Packages, which is subscribed to linux-signed in Ubuntu. https://bugs.launchpad.net/bugs/1766291 Title: 4.15-0-19-generic is world-readable 644 vs 600 for older kernels Status in linux-signed package in Ubuntu: Fix Committed Bug description: @apw Permissions changed from 600 to 644 in proposed: -rw------- 1 root root 8263536 Mar 7 17:36 /boot/vmlinuz-4.15.0-12-generic -rw------- 1 root root 8265464 Mar 16 10:49 /boot/vmlinuz-4.15.0-12-generic.efi.signed -rw------- 1 root root 8267632 Mar 16 18:49 /boot/vmlinuz-4.15.0-13-generic -rw------- 1 root root 8269560 Mar 30 23:13 /boot/vmlinuz-4.15.0-13-generic.efi.signed -rw------- 1 root root 8271728 Apr 4 15:26 /boot/vmlinuz-4.15.0-15-generic -rw------- 1 root root 8273656 Apr 16 16:07 /boot/vmlinuz-4.15.0-15-generic.efi.signed -rw-r--r-- 1 root root 8249080 Apr 22 00:32 /boot/vmlinuz-4.15.0-19-generic To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux-signed/+bug/1766291/+subscriptions -- Mailing list: https://launchpad.net/~kernel-packages Post to : kernel-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~kernel-packages More help : https://help.launchpad.net/ListHelp