SoylentNews
SoylentNews is people
https://soylentnews.org/breakingnews/

Title    Microsoft Security Update Breaks Dual-Boot Linux Systems Using Secure Boot
Date    Thursday August 22, @06:28PM
Author    janrinok
Topic   
from the dept.
https://soylentnews.org/breakingnews/article.pl?sid=24/08/22/1818251

Arthur T Knackerbracket has processed the following story:

Microsoft's Patch Tuesday for August 2024 includes a fix for a security vulnerability in the Grub2 boot loader, which is used by many Linux operating systems. Tracked as CVE-2022-2601, this flaw, discovered in 2022, could lead to an out-of-bounds write with a potential bypass of Secure Boot protection.

The Grub2 boot loader provides compatibility with the Secure Boot technology on PCs running Linux systems. After installing the new patch, Windows applies a Secure Boot Advanced Targeting (SBAT) policy to block vulnerable Linux boot loaders that could compromise OS security.

Microsoft explained that the SBAT value would not be applied to dual-boot systems with both Windows and Linux on the boot drive, so the patch was expected not to impact these systems. However, many users with dual-boot configurations have reported that the CVE-2022-2601 update still rendered booting into a Linux OS impossible.

The issue appears to affect various Linux distributions, including popular ones such as Ubuntu, Linux Mint, Zorin OS, Puppy Linux, and others. Affected systems typically display a "Security Policy Violation" error at boot, indicating a failed check on "shim SBAT data." Boot problems have been reported on both dual-boot systems and on Windows devices running Linux from an ISO image, USB drive, or optical media.

Microsoft's bulletin noted that only older Linux distros' ISOs were expected to experience boot issues following the CVE-2022-2601 patch. However, users with systems released in 2024 also seem to be affected. The only reliable way to restore a bootable state appears to be disabling Secure Boot entirely. Alternatively, users can follow the steps to remove the SBAT policy introduced by Microsoft this past week.


Original Submission

Links

  1. "following story" - https://www.techspot.com/news/104376-microsoft-security-update-breaks-dual-boot-linux-systems.html
  2. "CVE-2022-2601" - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-2601
  3. "Secure Boot" - https://www.techspot.com/tag/secure+boot/
  4. "ISO image" - https://github.com/ventoy/Ventoy/issues/2947
  5. "follow the steps" - https://discourse.ubuntu.com/t/sbat-revocations-boot-process/34996
  6. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=63584

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, Microsoft Security Update Breaks Dual-Boot Linux Systems Using Secure Boot on 2024-11-07 06:54:09