The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded.
https://bugzilla.redhat.com/show_bug.cgi?id=2388707
https://bugzilla.redhat.com/show_bug.cgi?id=2198977
https://bodhi.fedoraproject.org/updates/FEDORA-2024-2aa28a4cfc