Microsoft's May 2025 Hotfix Restores Linux Boot on Secure-Boot PCs

In This Article

After nine months of frustration for dual-boot users, Microsoft released an out-of-band patch on May 14 that resolves the Secure-Boot revocation issue introduced by the August 2024 cumulative updates. BleepingComputer

What Happened?

The August patch updated Secure Boot’s SBAT revocation list to block vulnerable GRUB2 bootloaders (CVE-2022-2601). Unfortunately, many Linux distributions still signed with the shim,3 or GRUB,3 identifiers, causing Secure Boot to refuse them. BleepingComputer

Who Was Affected?

  • Windows 10 & 11 dual-boot laptops and desktops
  • Windows Server 2012 R2 – 2022 hosting Hyper-V Gen-2 VMs with Linux guests
  • Any environment with Secure Boot enabled and outdated Linux shims

The Fix

Install KB5039213 (or the equivalent monthly roll-up). The update:

  1. Re-signs trusted shims and bootloaders.
  2. Rolls back the problematic SBAT policies.
  3. Adds telemetry to catch future breakage.

ECS Recommendations

Step

Action

Notes

1

Patch ASAP via WSUS or Intune.

Schedule reboot windows.

2

Re-enable Secure Boot if previously disabled.

Verify boot order first.

3

Check shim versions on Debian/Ubuntu (should be shim,4 or newer).

Use mokutil --sb-state.

4

Document BIOS settings post-update.

Capture screenshots for audit.

Need help? Contact ECS Support—our team can validate your dual-boot fleet remotely.

Browse All Insights