It already has 234 entries, all issued within a year of each other. How much space does a UEFI BIOS typically allocate for this list? Are you able to use this mechanism to revoke good BIOS signatures, is there an availability issue potentially created by misuse?
A new mechanism called SBAT (https://github.com/rhboot/shim/blob/main/SBAT.md) is now used to allow revocation of groups of bootloaders rather than individual hashes in order to mitigate the resource consumption
So the OS just doesn't do it automatically?
It does. Windows ships them as part of security updates, Linux distributions can use fwupd.
As noted in the other comment, Linux (if running fwupd) and Windows support doing it automatically, but the files are made public so other operating systems and distributions can also implement that.
I find it hard to square with: "In this blogpost we present the first public analysis of this UEFI bootkit, which is capable of running on even fully-up-to-date Windows 11 systems with UEFI Secure Boot enabled."
Microsoft has not yet chosen to revoke the vulnerable bootloader