Re: [SECURITY PATCH 49/73] fs: Disable many filesystems under lockdown

2025-02-19 Thread Andrew Hamilton
It seems this may impact some users attempting to use secure boot, I think I understand the reasoning behind this but maybe we should have something on the roadmap or issue tracker for what it would take to get these file systems more robust (fuzzing and/or test coverage)? Also should we update gr

Re: [SECURITY PATCH 00/73] GRUB2 vulnerabilities - 2025/02/18

2025-02-19 Thread Daniel Kiper via Grub-devel
Hi Didier, On Tue, Feb 18, 2025 at 07:33:03PM +, Didier Spaier wrote: > Hi Daniel and all, > > sorry for top posting but this is a question and a request, not a comment. > > maintaining a distribution alone I can't afford to carry as many patches as > Debian, so: could please mention the commi

Re: [SECURITY PATCH 00/73] GRUB2 vulnerabilities - 2025/02/18

2025-02-19 Thread Didier Spaier via Grub-devel
Hi, On 19/02/2025 12:03, Daniel Kiper via Grub-devel wrote: > Hi Didier, > > On Tue, Feb 18, 2025 at 07:33:03PM +, Didier Spaier wrote: >> Hi Daniel and all, >> >> sorry for top posting but this is a question and a request, not a comment. >> >> maintaining a distribution alone I can't afford

Re: [SECURITY PATCH 49/73] fs: Disable many filesystems under lockdown

2025-02-19 Thread Petr Řehák
Hello, why is there a lockdown for the NTFS file system, please? Is it vulnerable as well when no CVE exists for it? We are developers of computer-aided assistive technology for blind and visually impaired Windows users and this will prevent our GRUB to communicate with Windows, supplying ne