you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 2 years ago

Yeah, it actually looks like Ubuntu leaves the module signing key accessible to root on the filesystem:

https://wiki.ubuntu.com/UEFI/SecureBoot#Security_implications_in_Machine-Owner_Key_management

So root access basically gives you kernel access, if you just sign a malicious kernel module with the MOK.

  • source
  • parent