Chunks of the kernel you're about to load? The obvious thing to do is to copy them from userspace before you verify the signature. The running kernel can't be swapped out.
Power management, mobile and firmware developer on Linux. Security developer at nvidia. Ex-biologist. Content here should not be interpreted as the opinion of my employer. Also on Mastodon and Bluesky.
Re: Signing kexec blobs?
Date: 2013-12-04 12:35 am (UTC)