this post was submitted on 17 Jul 2023
11 points (100.0% liked)

Arch Linux

7612 readers
2 users here now

The beloved lightweight distro

founded 4 years ago
MODERATORS
 

Apparently os-prober is a security risk but tbh I don't really understand the issue. I've read its something to do with mounting all partitions as root, but you have to run grub-mkconfig as root anyway so I don't see how that could be used to gain root privileges? Does it not unmount them afterwards? And could you avoid the risk by just disabling it again after you've generated your grub.cfg?

The other option seems to be manually adding a Windows entry to /etc/grub.d/40_custom so I assume thats the recommended way to dual boot?

you are viewing a single comment's thread
view the rest of the comments

I don't have any hard data but I don't see that as a real security risk.