Release of the GNU GRUB 2.06 boot manager

After two years of development, a stable release of the modular multi-platform boot manager GNU GRUB 2.06 (GRand Unified Bootloader) has been presented. GRUB supports a wide range of platforms, including standard PCs with BIOS, IEEE-1275 platforms (PowerPC/Sparc64-based hardware), EFI systems, RISC-V, MIPS-compatible Loongson 2E processor hardware, Itanium systems, ARM, ARM64, and ARCS (SGI), as well as devices using the open-source CoreBoot package.

Key innovations:

  • Support for the SBAT (UEFI Secure Boot Advanced Targeting) mechanism has been added, addressing certificate revocation issues for boot loaders verified for UEFI Secure Boot. SBAT entails adding new metadata that is cryptographically signed and can additionally be included in lists of allowed or disallowed components for UEFI Secure Boot. The specified metadata allows manipulation of component version numbers upon revocation without the need for re-generating Secure Boot keys and without creating new signatures.
  • Support for the LUKS2 disk encryption format has been added, which differs from LUKS1 with a simplified key management system, the ability to use larger sector sizes (4096 instead of 512, reducing the load during decryption), the application of symbolic identifiers for partitions, and metadata backup capabilities with the potential for automatic restoration from a copy in case of damage.
  • Support for short MBR gaps (the area between the MBR and the start of the disk partition, which is used in GRUB to store part of the boot loader that doesn't fit in the MBR sector) has been discontinued.
  • Support for XSM (Xen Security Modules) has been added, allowing additional restrictions and privileges to be defined for the Xen hypervisor. of virtual machines and associated resources.
  • A lockdown mechanism has been implemented, similar to the corresponding set of restrictions in the Linux kernel. Lockdown blocks potential methods of bypassing UEFI Secure Boot, for instance, by prohibiting access to certain ACPI interfaces and CPU MSR registers, limiting DMA usage for PCI devices, blocking ACPI code imports from EFI variables, and preventing manipulations with input/output ports.
  • By default, the os-prober utility is disabled, which detects boot partitions of other operating systems and adds them to the boot menu.
  • Patches prepared by various Linux distributions have been backported.
  • Vulnerabilities BootHole and BootHole2 have been addressed.
  • The ability to build using GCC 10 and Clang 10 has been implemented.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster