Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Linux Patches Finally Make Hibernation Possible In Secure Boot / Lockdown Mode

Дата публикации: 09-10-2026 10:27:04

When booting the Linux kernel using UEFI SecureBoot, the kernel is put in the lockdown mode to restrict the ability to modify the running kernel image or leaking data from kernel memory. Kernel lockdown mode can also be manually enabled by the user/administrator. Among the limitations imposed in Linux's lockdown mode is no hibernation support. But that soon may be relieved with new patches proposed...

Основное содержимое страницы с новостью.

LINUX KERNEL

When booting the Linux kernel using UEFI SecureBoot, the kernel is put in the lockdown mode to restrict the ability to modify the running kernel image or leaking data from kernel memory. Kernel lockdown mode can also be manually enabled by the user/administrator. Among the limitations imposed in Linux's lockdown mode is no hibernation support. But that soon may be relieved with new patches proposed.

Matthew Garrett at NVIDIA sent out a request for comments (RFC) on new patches to allow system hibernation support when running in lockdown mode. Hibernation hasn't been supported in lockdown mode as it's ultimately an attack vector in current form for potentially compromising the system. When hibernating, the contents of the RAM are written to disk and then read back from disk into RAM when resuming the system. The kernel doesn't currently have the ability to ensure that the image written to disk wasn't tampered with at all and thus could be used by bad actors or malware for modifying the kernel image that is then loaded back into RAM or otherwise reading sensitive kernel memory.

Linux lockdown hibernate

Matthew Garrett's patches work to address that unencrypted and unauthenticated hibernation handling with TPM-backed security. The patches also involve adding audited TPM sessions in the kernel, generating a TPM signing key for audit sessions, and related infrastructure work. The hibernation image is ultimately securely signed to ensure that it wasn't tampered with during the hibernation process.

Those interested in system hibernation support when using the Linux kernel lockdown mode can see the RFC patches for this initial work to address this long-standing obstacle.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Nice to Know – Secure Boot in VMware07.9428-05-2026
2Faster Zswap With Patches To Batch The Writeback I/O06.4609-10-2026
3Ubuntu Linux kernel 7.2 installation guide012.8420-08-2026
4Linux 7.4 To Mainline Support For The Google Tensor G5, Pixel 10 Devices010.5605-10-2026
5Kage: Google Experimenting With Linux Driver Isolation Using In-Kernel LFI Sandboxes08.3207-10-2026
6Qualcomm kündigt Linux-Support für Snapdragon X2 an023.2824-09-2026
7openSUSE Leap 16.1 RC Released With New Immutable Mode011.8128-09-2026
8Arm Working On "TLBID" For Linux To Increase Performance On High Core Count CPUs04.5304-10-2026
9Linux 7.4 To Introduce The Steal Governor For Helping Virtualized Workloads010.7128-09-2026
10New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses09.2329-09-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 4.68. Источник: www.phoronix.com.