AT2k Design BBS Message Area
Casually read the BBS message area using an easy to use interface. Messages are categorized exactly like they are on the BBS. You may post new messages or reply to existing messages!

You are not logged in. Login here for full access privileges.

Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page
   Networked Database  Computer Support/Help/Discussion...   [1973 / 2000] RSS
 From   To   Subject   Date/Time 
Message   LWN.net    All   Many old shim versions are still accepted by secure boot   July 16, 2026
 6:40 AM *  

The CMU CERT Coordination Center has put out an advisory that many
exploitable versions of the shim binary, used to boot Linux on systems with
UEFI secure boot enabled, were never added to the revocation list.

An attacker with administrative privileges or the ability to modify
	the boot process could use one of the vulnerable shim bootloaders
	to bypass Secure Boot protections and execute arbitrary code before
	the operating system loads. Code executed during this early boot
	phase may achieve persistent compromise of the platform, including
	the ability to load unsigned or malicious kernel components that
	can survive system reboots and, in some cases, operating system
	reinstallation.

The advisory contains a list of vulnerable shims.

https://lwn.net/Articles/1082940/
--- SBBSecho 3.37-Linux
 * Origin: Palantir * palantirbbs.ddns.net * Pensacola, FL * (618:250/24)
  Show ANSI Codes | Hide BBCodes | Show Color Codes | Hide Encoding | Hide HTML Tags | Show Routing
Previous Message | Next Message | Back to Computer Support/Help/Discussion...  <--  <--- Return to Home Page

VADV-PHP
Execution Time: 0.0129 seconds

If you experience any problems with this website or need help, contact the webmaster.
VADV-PHP Copyright © 2002-2026 Steve Winn, Aspect Technologies. All Rights Reserved.
Virtual Advanced Copyright © 1995-1997 Roland De Graaf.
v2.1.250224