The CMU CERT Coordination Center has put out an advisory that many
exploitable versions of the shim binary, used to boot Linux on systems with
UEFI secure boot enabled, were never added to the revocation list.


An attacker with administrative privileges or the ability to modify
the boot process could use one of the vulnerable shim...