TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Red Hat and CentOS systems aren’t booting due to BootHole patches

113 pointsby thgalmost 5 years ago

12 comments

cvwilliamsalmost 5 years ago
As usual, there are prophetic warnings from Linus:<p><a href="https:&#x2F;&#x2F;yarchive.net&#x2F;comp&#x2F;linux&#x2F;efi.html" rel="nofollow">https:&#x2F;&#x2F;yarchive.net&#x2F;comp&#x2F;linux&#x2F;efi.html</a><p>BIOS should be simple, because it is buggy anyway. Handing over to a bootloader in the MBR is all that a BIOS should do. Now one is at the mercy of NVRAM, grub2 and loads of gratuitous complexity.
评论 #24020455 未加载
评论 #24028021 未加载
评论 #24021501 未加载
评论 #24021957 未加载
评论 #24022515 未加载
评论 #24021073 未加载
评论 #24020217 未加载
fideloperalmost 5 years ago
Ubuntu had this as well, but got a release out quickly so it seems to have not been too huge an issue.<p>Bug report: <a href="https:&#x2F;&#x2F;bugs.launchpad.net&#x2F;cloud-init&#x2F;+bug&#x2F;1877491" rel="nofollow">https:&#x2F;&#x2F;bugs.launchpad.net&#x2F;cloud-init&#x2F;+bug&#x2F;1877491</a><p>Description&#x2F;remediation: <a href="https:&#x2F;&#x2F;wiki.ubuntu.com&#x2F;SecurityTeam&#x2F;KnowledgeBase&#x2F;GRUB2SecureBootBypass?_ga=2.62301103.2044889230.1596151413-1800768090.1596151413" rel="nofollow">https:&#x2F;&#x2F;wiki.ubuntu.com&#x2F;SecurityTeam&#x2F;KnowledgeBase&#x2F;GRUB2Secu...</a>
评论 #24020470 未加载
nullcalmost 5 years ago
Number of users saved from attack by secure boot: 0 Number of systems bricked by fixes to secure boot vulnerabilities: Many<p>Sad to see TSA in software form.
cpncrunchalmost 5 years ago
We have a centos 8 server that has been bricked, and there doesn&#x27;t seem to be any solution right now. Downgrading the packages shows &quot;lowest version already installed, cannot downgrade it.&quot;, and I can&#x27;t manually install the old packages because there doesn&#x27;t seem to be any way of getting them. Someone says to use <a href="http:&#x2F;&#x2F;mirror.centos.org&#x2F;centos-8&#x2F;8.2.2004&#x2F;BaseOS&#x2F;x86_64&#x2F;os&#x2F;Packages&#x2F;" rel="nofollow">http:&#x2F;&#x2F;mirror.centos.org&#x2F;centos-8&#x2F;8.2.2004&#x2F;BaseOS&#x2F;x86_64&#x2F;os&#x2F;...</a> but that seems to have the very latest packages and even after updating the affected ones it still fails to boot.
评论 #24021144 未加载
评论 #24020471 未加载
评论 #24021404 未加载
noahblissalmost 5 years ago
Hey all, just wanted to make you aware of the mortar project here: <a href="https:&#x2F;&#x2F;github.com&#x2F;noahbliss&#x2F;mortar" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;noahbliss&#x2F;mortar</a><p>It takes a comprehensive approach rather than piecemeal like a lot of these patches, leveraging technology already in your system to build a conceptually airtight and fully audited system. Happy to get some of your opinions on it, constructive criticism, and pull requests!
ginkoalmost 5 years ago
I still don&#x27;t understand why this even needed to be fixed. Finding a way to circumvent UEFI DRM seems to be a good thing.
评论 #24020868 未加载
qalmakkaalmost 5 years ago
I&#x27;m kind of out of the loop - is BootHole a UEFI or GRUB2 vulnerability?
评论 #24021825 未加载
benttoothpastealmost 5 years ago
The most secure boot is the one that does not take place ;) So maybe there is a method in this madness?
fomine3almost 5 years ago
It seems that it&#x27;s really critical issue. How does this patch pass Red Hat&#x27;s test?
评论 #24019962 未加载
cpncrunchalmost 5 years ago
Fixes now available for RHEL, still waiting for CentOS.
Jonnaxalmost 5 years ago
Is Secure Boot on Linux actually secure?<p>I remember reading it was like a signed loader and that&#x27;s it. But I presume that&#x27;s incorrect?
评论 #24020320 未加载
评论 #24020652 未加载
评论 #24020300 未加载
fortran77almost 5 years ago
That&#x27;s the great thing about open source, though. You guys can fix it yourself. Me, I&#x27;m stuck on Windows 10.
评论 #24021483 未加载