[PATCH 2/2 v2] efi_loader: hash the image once before checking against db/dbx