
Important 88737 Symptoms
The installation of the Operating System image will be denied and “SECUREBOOT: Image DENIED.” will be reported in vmware.log.
Below goes the list of the impacted Linux Operating Systems.
- RHEL 8.0~8.4, 7.x
- CentOS 8.0~8.5, 7.x
- Oracle Linux 8.0~8.3, 7.x
- AlmaLinux 8.4
- Rocky Linux 8.4
- Photon OS 4.0GA, 3.0 GA & Rev 2 & Rev 3, 2.0
- Ubuntu LTS 20.04~20.04.4, 18.04~18.04.5 and earlier
- Ubuntu Non-LTS 21.04, 20.10, 19.10, 19.04, 18.10 and earlier
- Debian 10.9 and earlier
- SLE 12SP0~SP5, 15SP0-SP2
Cause
This is caused due to the Secure Boot deny list (dbx) is updated to prevent vulnerable bootloaders from being used. For more information, refer to VMware response to GRUB2 security vulnerability CVE-2020-10713 (80181)
Resolution
- Create the SecureBoot Virtual Machine with Hardware version 19 (or earlier).
- After the installation is completed, update the vulnerable bootloader of the VM to a newer and fixed version, refer to VMware response to GRUB2 security vulnerability CVE-2020-10713 (80181)
- Upgrade the Virtual Machine’s Hardware version to 20.
Workaround
Create the Virtual Machine with Secureboot disabled instead.