Don't worry, the whole thing is that GNU boot contains proprietary firmware for testing coreboot. The only distros affected are GNU Boot and Canoe Boot. Upstream coreboot has that testing firmware there intentionally so it's silly to call it "affected".
FSF is doing great stuff for the world but I think FOSS is kinda held back by being led by nerds that are "a bit different". (edit: I mean that with respect. These nerds are surely nice people and great coders but imo not great philosophical leaders)