Article 770DP Many old shim versions are still accepted by secure boot

Many old shim versions are still accepted by secure boot

by
corbet
from LWN.net on (#770DP)
The CMU CERT Coordination Center has put out an advisory that manyexploitable versions of the shim binary, used to boot Linux on systems withUEFI secure boot enabled, were never added to the revocation list.

An attacker with administrative privileges or the ability to modifythe boot process could use one of the vulnerable shim bootloadersto bypass Secure Boot protections and execute arbitrary code beforethe operating system loads. Code executed during this early bootphase may achieve persistent compromise of the platform, includingthe ability to load unsigned or malicious kernel components thatcan survive system reboots and, in some cases, operating systemreinstallation.

The advisory contains a list of vulnerable shims.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments