When booting the Linux kernel using UEFI SecureBoot, the kernel is put in the lockdown mode to restrict the ability to modify the running kernel image or leaking data from kernel memory. Kernel lockdown mode can also be manually enabled by the user/administrator. Among the limitations imposed in Linux's lockdown mode is no hibernation support. But that soon may be relieved with new patches proposed...

When booting the Linux kernel using UEFI SecureBoot, the kernel is put in the lockdown mode to restrict the ability to modify the running kernel image or leaking data from kernel memory. Kernel lockdown mode can also be manually enabled by the user/administrator. Among the limitations imposed in Linux's lockdown mode is no hibernation support. But that soon may be relieved with new patches proposed.
Matthew Garrett at NVIDIA sent out a request for comments (RFC) on new patches to allow system hibernation support when running in lockdown mode. Hibernation hasn't been supported in lockdown mode as it's ultimately an attack vector in current form for potentially compromising the system. When hibernating, the contents of the RAM are written to disk and then read back from disk into RAM when resuming the system. The kernel doesn't currently have the ability to ensure that the image written to disk wasn't tampered with at all and thus could be used by bad actors or malware for modifying the kernel image that is then loaded back into RAM or otherwise reading sensitive kernel memory.
Matthew Garrett's patches work to address that unencrypted and unauthenticated hibernation handling with TPM-backed security. The patches also involve adding audited TPM sessions in the kernel, generating a TPM signing key for audit sessions, and related infrastructure work. The hibernation image is ultimately securely signed to ensure that it wasn't tampered with during the hibernation process.
Those interested in system hibernation support when using the Linux kernel lockdown mode can see the RFC patches for this initial work to address this long-standing obstacle.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Nice to Know – Secure Boot in VMware | 0 | 7.94 | 28-05-2026 |
| 2 | Faster Zswap With Patches To Batch The Writeback I/O | 0 | 6.46 | 09-10-2026 |
| 3 | Ubuntu Linux kernel 7.2 installation guide | 0 | 12.84 | 20-08-2026 |
| 4 | Linux 7.4 To Mainline Support For The Google Tensor G5, Pixel 10 Devices | 0 | 10.56 | 05-10-2026 |
| 5 | Kage: Google Experimenting With Linux Driver Isolation Using In-Kernel LFI Sandboxes | 0 | 8.32 | 07-10-2026 |
| 6 | Qualcomm kündigt Linux-Support für Snapdragon X2 an | 0 | 23.28 | 24-09-2026 |
| 7 | openSUSE Leap 16.1 RC Released With New Immutable Mode | 0 | 11.81 | 28-09-2026 |
| 8 | Arm Working On "TLBID" For Linux To Increase Performance On High Core Count CPUs | 0 | 4.53 | 04-10-2026 |
| 9 | Linux 7.4 To Introduce The Steal Governor For Helping Virtualized Workloads | 0 | 10.71 | 28-09-2026 |
| 10 | New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses | 0 | 9.23 | 29-09-2026 |