Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Oh, no! Windows Security Update Breaks Dual-Boot Linux Systems
It's FOSS ^ | 22 August 2024 | Sourav Rudra

Posted on 08/27/2024 4:58:51 AM PDT by ShadowAce

Microsoft is known for their signature, “my way or the highway” approach when it comes to their offerings, with the Windows operating system being the most prominent one among those.

Many in the FOSS community disagree with that approach, with a strong rejection of such practices, suggesting people go for more open options for their operating systems and applications, and I agree with them.

Unfortunately, that same approach has now affected many Linux distribution users, who were sent scampering searching for a fix to a problem caused by a Windows update (who would've expected that?).

Microsoft Slips Up: Linux Users Beware!

a screenshot showing the verifying shim sbat data failed error on a dual boot system with windows and linux Source: paku1234

First spotted by Ars Technica, a monthly Windows update pushed on August 13 that included a fix to a two-year-old vulnerability, CVE-2022-2601, with an 8.6 CVSS severity rating, caused dual-boot systems with Windows and Linux distros to not boot.

That fix was meant to tackle an issue with the GRUB bootloader, which allowed malicious actors from carrying out-of-bound writes, and possibly bypass secure boot.

But, it caused some collateral damage in the process. After updating, many users, including users of Ventoy, and Ubuntu 24.04, reported that they were shown the following error:

Verifying shim SBAT data failed: Security Policy Violation

Something has gone seriously wrong: SBAT self-check failed: Security Policy Violation

This update installed an SBAT, which is an acronym for Secure Boot Advanced Targeting, a Linux-focused method for discarding various components in the boot path using generation numbers embedded into the EFI binaries. (apologies for the jargon)

However, this mechanism was meant to run with devices only running Windows, and, according to Microsoft, this should not have caused any issues on dual-boot systems, at least on newer Linus distributions.

But, as we know already, it did. 😑

Following these revelations, in a statement, Microsoft mentioned that they were aware of “some secondary boot scenarios are causing issues for some customers”, and that they were working with their Linux partners to investigate and address the issue.

Thankfully, the community has come to the rescue, with manutheeng, a member of the Linux Mint forums, finding a solution for Ubuntu in an old post on the Ubuntu forums.

The Solution

 sudo mokutil --set-sbat-policy delete 

The above steps should also work with any Ubuntu-based Linux distribution. If that doesn't work, then you might be facing what a Framework laptop user faced.

Closing Thoughts

If dual-boot systems were more common, then this issue would've been treated with more haste, like the CrowdStrike incident that took place last month, but that was not Microsoft's fault.

So, it's better than nothing. 🙂

Ultimately, there's still the matter of Secure Boot being an absolute mess, that has left many people questioning whether this could've been implemented in a better way.

I think that it could've, the PC industry rushed its implementation before it was ready.


TOPICS: Computers/Internet
KEYWORDS: linux; windows
Navigation: use the links below to view more comments.
first 1-2021-31 next last
Thanks to Pete from Shawnee Mission for the ping!
1 posted on 08/27/2024 4:58:51 AM PDT by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; JosephW; martin_fierro; Still Thinking; zeugma; Vinnie; ironman; Egon; raybbr; AFreeBird; ...

2 posted on 08/27/2024 4:59:07 AM PDT by ShadowAce (Linux - The Ultimate Windows Service Pack )
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Meh. I have a dual boot sytem. Linux Mint 17 or Linux Mint 21. Tossed Winders 10 years ago.


3 posted on 08/27/2024 5:11:02 AM PDT by Bloody Sam Roberts (Perfection is impossible. But if you pursue perfection...you may achieve excellence.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

“DOS isn’t done until Lotus won’t run.”

Old saying from early PC days, 40ish years ago.


4 posted on 08/27/2024 5:27:23 AM PDT by FreedomPoster (Islam delenda est)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bloody Sam Roberts

Some distros are in virtual box and others stand alone on hand me down boxes.


5 posted on 08/27/2024 5:36:35 AM PDT by wally_bert (I cannot be sure for certain, but in my personal opinion I am certain that I am not sure..)
[ Post Reply | Private Reply | To 3 | View Replies]

To: ShadowAce

Anything that is labelled “advanced targeting” is not an accident. Yeah, targeting from MS. It offensive not defensive security. This was intentional and violates antitrust.

They think folks are stupid. And that arrogance and deceptive practice is why I told them to take a hike years ago.


6 posted on 08/27/2024 5:44:06 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

I am so glad I still have W7


7 posted on 08/27/2024 5:50:19 AM PDT by ducttape45 (Jeremiah 17:9, "The heart is deceitful above all things, and desperately wicked: who can know it?")
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

I have dual boot but windows is not allowed to connect to the web, therefor, not allowed to get updates. It’s a fresh win 7 pro install that is several years old.


8 posted on 08/27/2024 5:54:03 AM PDT by Pollard (Will work for high tunnel money!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Pollard

I thought it was standard practice to just disable secure boot before installing Linux anyhow?

If my memory is right all the instructions going way back have said to do this first?


9 posted on 08/27/2024 6:02:36 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 8 | View Replies]

To: ducttape45

Same here.

Runs a couple of CD rom games I play once in a while.

I like the built in chess game that I can almost never beat.


10 posted on 08/27/2024 6:03:12 AM PDT by wally_bert (I cannot be sure for certain, but in my personal opinion I am certain that I am not sure..)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Openurmind

My laptop is too old to have secure boot in the bios so I don’t have any experience with that.


11 posted on 08/27/2024 6:07:53 AM PDT by Pollard (Will work for high tunnel money!)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Pollard

I think I remember having trouble booting from a Linux USB with even the old legacy bios. I had to go turn secure boot off before it would allow me. But it probably depends on the make.


12 posted on 08/27/2024 6:16:05 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 11 | View Replies]

To: ShadowAce

Won’t break my dual boot- windows 7 which i use only in offline mode for windows only programs and games.


13 posted on 08/27/2024 6:32:37 AM PDT by Bob434
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

This is like a car manufacturer disabling your car because you took it to an independent shop instead of their dealer shop.

How many people would actually put up with that arrogant concept and practice? Apparently a LOT. Because they just keep doing it.


14 posted on 08/27/2024 6:41:23 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

This is like a car manufacturer disabling your car because you took it to an independent shop instead of their dealer shop.

How many people would actually put up with that arrogant concept and practice? Apparently a LOT. Because they just keep doing it.


15 posted on 08/27/2024 6:41:23 AM PDT by Openurmind (The ultimate test of a moral society is the kind of world it leaves to its children. ~ D. Bonhoeffer)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

At this point in my life there are only a handful of use cases for me to run Windows directly on hardware. I don’t play games but that would be one of them. As the author pointed out, Secure Boot is a mess from the ground up and it’s only on locked-down corporate windows workstations where it makes sense. Most hobbyists, developers, and dev-ops folks who using linux on a day-to-day basis aren’t dual-booting and likely have disabled secure boot already.

I recently replaced my laptop and immediately replaced the hard drive with a larger model and installed Linux. The first thing I disabled in the BIOS was the Secure Boot functionality.


16 posted on 08/27/2024 6:43:42 AM PDT by mjustice (Apparently common sense isn't so common.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

My 2 laptops are duel boot Manjaro Linux and Windows 11 but my desktop has a hard drive hot swap bay and and an OS on each hard drive that I swap out as I need them ,LOL


17 posted on 08/27/2024 6:58:43 AM PDT by butlerweave
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Windows ain’t done till Linux don’t run?


18 posted on 08/27/2024 7:14:06 AM PDT by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ducttape45

Me too.


19 posted on 08/27/2024 7:15:36 AM PDT by Carriage Hill (A society grows great when old men plant trees, in whose shade they know they will never sit.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: butlerweave

This scenario puts the “duel” in “duel boot”!


20 posted on 08/27/2024 7:18:59 AM PDT by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-31 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson