Related Vulnerabilities: CVE-2020-26541  

The Linux kernel does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

Severity Medium

Remote No

Type Certificate verification bypass

Description

The Linux kernel does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.

AVG-1878 linux 5.12.arch4-1 Medium Not affected

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=56c5812623f95313f6a46fbf0beee7fa17c68bbf

This codepath is only executed when the kernel configuration option CONFIG_LOAD_UEFI_KEYS is enabled, which is not the case for the kernels provided by Arch Linux.