[Bug 1798384] [NEW] Grub allows to load unsigned kernel even BIOS enabled secure boot

Darren Wu darren.wu at canonical.com
Wed Oct 17 13:55:46 UTC 2018


Public bug reported:

The grub 2.02 in bionic still has the insecure commands which "linux"
and "initrd", it allows to load unsigned kernel and initrd.

Even BIOS has forced the secure boot, when grub boot menu shows and stay
few seconds and it allows to enter to grub command-line by press 'c'. In
the grub command-line, that's easy to load unsigned kernel by 'linux'
and 'initrd' commands.

Suggest to remove the 'linux' and 'initrd' from grub commands list.

** Affects: grub2 (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to grub2 in Ubuntu.
https://bugs.launchpad.net/bugs/1798384

Title:
  Grub allows to load unsigned kernel even BIOS enabled secure boot

Status in grub2 package in Ubuntu:
  New

Bug description:
  The grub 2.02 in bionic still has the insecure commands which "linux"
  and "initrd", it allows to load unsigned kernel and initrd.

  Even BIOS has forced the secure boot, when grub boot menu shows and
  stay few seconds and it allows to enter to grub command-line by press
  'c'. In the grub command-line, that's easy to load unsigned kernel by
  'linux' and 'initrd' commands.

  Suggest to remove the 'linux' and 'initrd' from grub commands list.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/1798384/+subscriptions



More information about the foundations-bugs mailing list