Package: linux-image-amd64Severity: important
Version: 7.1.7+deb14-amd64
Distribution: sid (testing)

Description:
Kernel compiled without CONFIG_CRYPTO_SHA384 despite IMA being enabled.
Causes boot-time error: "[ 0.607362] ima: can not allocate sha384 (reason: -2)"

System Information:
- Kernel: 7.1.7+deb14-amd64
- Distribution: Debian testing (sid)
- Architecture: amd64
- Kernel packages installed: linux-image-amd64, 
linux-image-amd64-signed-template

Evidence:
1. /proc/crypto | grep sha384 → no output
2. /boot/config-$(uname -r) shows:
   - CONFIG_CRYPTO_SHA256=y
   - CONFIG_CRYPTO_SHA512=m
   - CONFIG_CRYPTO_SHA384 → MISSING entirely
   - CONFIG_IMA=y (enabled)

Impact:
IMA subsystem cannot allocate SHA-384 hash algorithm at boot time,
resulting in error message. Default IMA hash is SHA-256, but some
component requests SHA-384 which is unavailable.

Proposed Fix:
Enable CONFIG_CRYPTO_SHA384=y (or =m) in kernel configuration.

References:
https://lists.debian.org/debian-devel/ [link to relevant thread if any]


Sent with Proton Mail secure email.

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to