Microsoft is updating Secure boot 22-24 july (posted June 9, 2026)

Condobloke

Well-Known Member
Joined
Apr 30, 2017
Messages
13,384
Reaction score
11,319
Credits
96,224


1st reply there states :

I'm not sure if you know but Microsoft is updating secure bootloader end of july.
The security update applies only to the following Windows versions, none of which are current versions:

  • Windows Server 2012
  • Windows 8.1 and Windows Server 2012 R2
  • Windows 10, version 1507
  • Windows 10, version 1607 and Windows Server 2016
  • Windows 10, version 1809 and Windows Server 2019
  • Windows 10, version 20H2
  • Windows 10, version 21H1
  • Windows 10, version 21H2
  • Windows 10, version 22H2
  • Windows Server 2022
  • Windows 11, version 21H2
  • Windows 11, version 22H2
  • Azure Stack HCI, version 1809
  • Azure Stack Data Box, version 1809 (ASDB)
Source: KB5012170: Security update for Secure Boot DBX

I'm not sure if this is normal proceder or if they are cracking down on what they think is "unsecure" OS.
Read the link and you will understand the purpose and scope of the update. Several CVE's have been uncovered and the update patches the vulnerabilities.

Anyway, how can i prepare myself from this update? i have been reading on website about this but i'm not that technical to understand it.
You don't need to do anything if you are running a reasonably current version of Windows. Check Settings > System > About > Windows Information to see what Windows version you are running. If the version you are running (probably 25H2 if you update regularly) is not listed, the update does not apply to you.
 
Updates to 8.1 and 10. Both are EOL and have been.

There must be enough stragglers for MSFT to feel that they need to ship a patch to people using those versions of Windows.
 
Turns out MS has been idling on restricting vulnerable Linux shims for years, and they are signed by the old 2011 certificate. So, anyone using Linux while relying on secure-boot enabled indeed must care a lot to get this updated:

 
As I have secure boot disabled on my Tower's Motherboard and not using windoze...I don't care.

1784675108504.gif
 
Updates to 8.1 and 10. Both are EOL and have been.

Actually you can buy extended support for Win 10. They don't advertise this, and I'm not supposed to tell people about it, (at my job). But I'm also not supposed to tell people about Libre Office when they find out that MS Office isn't included with Windows anymore, and you can't buy a perpetual license either. Instead they have to pay $100 for a one year subscription for a single account.

What I do instead show people the Libre office website, tell them to take a picture before I close the window then delete cookies and browsing history.
 
Last edited:
As I have secure boot disabled on my Tower's Motherboard and not using windoze...I don't care.

View attachment 32739

Same here, other than one laptop with windows buried underneath piles of boxes and blankets to keep winblows from listening in. I need to keep for a while. Such a shame too. It's a nice laptop!

Other than to let Linux users they might need to disable Secure Boot if they haven't already, why would we care?
 
Actually you can buy extended support for Win 10.

I know. I've mentioned it many times. It's still EOL. The caveat is that you can pay about $30 per year to keep getting some patches.
 
UEFI, Secure Boot, Device hardening...

These things just came up in my course and this thread is on topic. I have a question, or questions.

I just crammed an entire week of coursework into my brain in about 4 hours, so I hope this makes sense.

Obviously malicious actors will infect the firmware of computers if given the chance. Unless they're just asses trying to destroy a computer, they have a some reason for spreading malware to the UEFI/ BIOS. Getting valuable information seems to be the number one reason, or hijack the PC for a botnet, I know there are others. But since the majority of personal computers are Windows based, and malware is typically spread in .exe files that won't execute in a Linux system, why would we Linux users be bothered by any of this?

I can easily see how this might be important on a dual boot system....


And is it wiser to enable Secure Boot in a Linux system?
 
Last edited:
Hi, Sherri, I'll answer what I can answer, and leave the rest to others more knowledgeable. ;)

A.

On

,... why would we Linux users be bothered by any of this?

I can easily see how this might be important on a dual boot system....

It may or may not be important. You can actually run Windows with Secure Boot switched off by tweaking a part of Registry, but it may be contra-indicated if by doing so, it compromises the ability of Windows to download and install all of its copious updates.

If that proves to be the case, then you might want to run your dual-boot or multi-boot using a Linux distro or distros that run under Secure Boot. So

B.

On

And is it wiser to enable Secure Boot in a Linux system?

A significant number of Linux distros will not run under Secure Boot. Some of these can be run by going through hoops to generate your own Machine Keys that SB will recognise, and some cannot.

Arch and Arch-based distros fall into the "cannots", as does Debian-based "Parrot Security/Home".

Fedora and Fedora-based fall into the category of "running through hoops".

Since Brian began this Thread, I have undertaken to check which in my stable of 85 distros, will, will not, and maybe.

I am approaching an end to that process, and will publish my results in a separate thread when I can.

HTH

Chris
 
A significant number of Linux distros will not run under Secure Boot.

I found this on the Linux Mint forums

" No, Secure Boot is not strictly required for Linux Mint 22.1, but it is highly recommended to enable it for enhanced security, as most modern Linux distributions, including Linux Mint, are now signed for Secure Boot compatibility, allowing you to boot the system securely on compatible hardware. "




Some of these can be run by going through hoops to generate your own Machine Keys that SB will recognise, and some cannot.

No thank you!
 
Last edited:
Am I incorrect about this?

Yes and no.

It is of importance to server maintainers, but some of it is applicable at the desktop level. I know next to nothing about servers.

Near the bottom it mentions fwupd, a small suite which includes fwupdmgr.

The latter, fwupdmgr can be used by the desktop user (some commands require sudo) to see how their certificates are set up (status commands without sudo, making changes with sudo).

If you go to the MOK (Machine Owner Key) level, and generate your own certificates (Fedora is one example), then you are committed to reproducing that with every kernel release or update.

I have held off on trying this with Fedora, because with my 85 distros on one rig, I am not in a hurry to have changes ripple through, perhaps adversely, to all of them to operate.

I will be waiting a couple of days to see if the 22-24 July changes have any impact on my current setup before I go further, and then publish as referenced earlier.
 
Yes and no.

It is of importance to server maintainers, but some of it is applicable at the desktop level. I know next to nothing about servers.

I wrote about this in the discussion forum for the course I'm taking right now.

They encouraged me to write about the things I'm curious about after I wondering if Windows devices running on ARM architecture used the same firmware.

They have no idea what they just gave me license to do...
 


Follow Linux.org

Staff online


Latest posts

Top