On October 8, 2026, Matthew Garrett submitted RFC patches proposing TPM-backed safeguards that would let Linux hibernate while kernel lockdown is active. The proposal describes a way to protect the saved system image; it is not a statement that the change has been implemented.

Why kernel lockdown restricts hibernation

Hibernation writes the system’s memory state to storage, then restores it when the machine resumes. That saved image can contain sensitive information, and an attacker who alters it while the computer is powered down could affect the kernel state loaded on resume.

Kernel lockdown restricts operations that could undermine the kernel’s integrity. The security problem is therefore not just whether someone can read the stored image: the system also needs to know that the image it restores is trustworthy. Encryption can help keep stored data confidential, but encryption alone does not establish that a trusted kernel created the image.

What safeguards the RFC proposes

The proposed design combines TPM-backed security with audited TPM sessions in the kernel, a TPM signing key for those sessions, and a signed hibernation image. A Trusted Platform Module (TPM) is a hardware-backed security component used to support cryptographic operations. Signing an image addresses its authenticity; encryption addresses the separate question of who can read its contents.

Together, these measures are intended to protect the saved state that Linux restores after hibernation, so the system can preserve the kernel-integrity protections associated with lockdown. They remain proposed components of Garrett’s RFC.

How Secure Boot, lockdown, suspend, and hibernation differ

On EFI-enabled x86 or arm64 systems, booting in UEFI Secure Boot mode automatically enables kernel lockdown. That relationship applies to those specified platforms and boot conditions.

Suspend-to-RAM and hibernation store state differently. Suspend keeps the system state in powered memory. Hibernation writes that state to storage and restores it later, making the saved image central to the security concern addressed by the RFC.