Reply to post:

GRUB2, you're getting too bug for your boots: Config file buffer overflow is a boon for malware seeking to drill deeper into a system

Nate Amsden

Sure does..

also seems to affect those who specifically use secureboot(since without that I mean any admin can set any kernel or whatever to load in grub signed or not), I'm not sure how many do, I don't think I have had it enabled on any of my systems. Just checked my personal Linux laptop and it is not enabled(https://techoverflow.net/2019/05/23/how-to-check-if-secure-boot-is-enabled-on-ubuntu/ ), and checked one of my ESX Ubuntu VMs and says EFI not supported, so that rules out an issue on any of my 700+ linux VMs and probably the windows VMs too. Checked a HP Gen10 system with Ubuntu 20 and says it's disabled, Checked an older Gen8 with Ubuntu 16 and says EFI not supported.

An interesting question for me that wasn't raised in the article not sure if it is an issue or not, but if/when this cert is revoked by the vendor(I assume vendor like HP, Dell, etc) could it prevent the system from booting(assuming Secure boot is enabled) if the grub update isn't already applied?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon