Bug#1020713: initramfs-tools: RESUME=auto probably a security hole

2022-09-25 Thread Christoph Anton Mitterer
Am 25. September 2022 20:13:26 MESZ schrieb Bastian Blank : >On Sun, Sep 25, 2022 at 08:05:29PM +0200, Christoph Anton Mitterer wrote: >But an attacker can already modify the kernel command line. Secure boot >up until recently was completely incompatible with hibernation, so >nothing here appli

Bug#1020713: initramfs-tools: RESUME=auto probably a security hole

2022-09-25 Thread Bastian Blank
On Sun, Sep 25, 2022 at 08:05:29PM +0200, Christoph Anton Mitterer wrote: > Isn't that a rather simple security hole for an attacker with local access > to the system to easily defeat full disk encryption with dm-crypt (in > combination with booting from a safe USB) and to a certain extent secure b

Bug#1020713: initramfs-tools: RESUME=auto probably a security hole

2022-09-25 Thread Christoph Anton Mitterer
Package: initramfs-tools Version: 0.142 Severity: important Tags: security Hey. According to initramfs.conf(5): > RESUME > Specifies the device used for suspend-to-disk (hibernation), > which the initramfs code should attempt to resume from. If this >