Announcement

Collapse
No announcement yet.

Microsoft UEFI dbx?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Microsoft UEFI dbx?

    Using K 24.04 now. In Discover updates, I see this: Microsoft UEFI dbx, 20241101 -> 20260402, and base files.
    What does it mean?
    That is to be ignored, right? (There is no MS Windows here.)
    An intellectual says a simple thing in a hard way. An artist says a hard thing in a simple way. Charles Bukowski

    #2
    Google AI


    The Microsoft UEFI dbx is a Secure Boot forbidden signature database—essentially a security "blacklist"—stored on your motherboard that prevents vulnerable or malicious bootloaders from running when your Kubuntu system starts up. [1]
    How UEFI dbx Works
    • The Blacklist: It holds cryptographic signatures of known compromised or vulnerable boot code, instructing your firmware to refuse to load them [0.17]. [1]
    • Security Protection: It protects your computer from severe boot-level exploits like the BootHole vulnerability. [1]
    • Ecosystem Source: While labeled with Microsoft, it acts as an industry-standard revocation list managed across operating systems, including Linux distributions like Kubuntu via firmware update tools (fwupd) [0.16]. [1]
    Should You Install It?
    • Recommendation: You should generally install UEFI dbx updates to keep your system protected against newly discovered boot vulnerabilities. [1]
    • Troubleshooting: If you see a persistent or repeating notification to install the same dbx update repeatedly in Kubuntu's Discover software center, it is usually a harmless firmware NVRAM limitation or a known metadata glitch rather than a broken system [0.14]. [1]
    Slava Ukraini! 🇺🇦
    Windows no longer obstruct my view.
    Using Kubuntu Linux since March 23, 2007.
    "It is a capital mistake to theorize before one has data." - Sherlock Holmes

    Comment


      #3
      So it's just data about bad boys, and it is not any interfering code into UEFI firmware -- so it sound like to me => safe.
      An intellectual says a simple thing in a hard way. An artist says a hard thing in a simple way. Charles Bukowski

      Comment


        #4
        I never have Secure Boot enabled, but I took that update anyway. It's just a bunch of data.
        An intellectual says a simple thing in a hard way. An artist says a hard thing in a simple way. Charles Bukowski

        Comment

        Users Viewing This Topic

        Collapse

        There are 0 users viewing this topic.

        Working...
        X