Reinstall grub + BIOS + fully encrypted LUKS partitions, will this work?

Please note my comment here. This might not be as big of a vulnerability as it first appears.

If you still want to fix the vulnerability, you’ve got a bit of a complex setup that not a lot of users are likely to have experience with.

To be sure about how something will work on your system without changing it, I’d recommend creating a VM and testing the changes there:

  1. Install virtualbox
  2. Replicate your existing install (partitions/disks/OS’s) in a new VM
  3. Snapshot the VM
  4. Attempt to re-install grub

If you bork the VM, you can revert to a snapshot, while gaining knowledge of what not to do without impacting your actual system.

If you encounter specific errors, you can report back here and we can try to assist with those.

Notes:

  • With your system being encrypted, it is especially important to have a backup of your data in the event that it becomes inaccessible. That way if things go awry, at the very least you’ll be able to re-setup your system without losing that.
  • Fixing this vulnerability is not something that needs to be rushed. You can continue to update your system to future updates without re-installing grub and your system should continue to function like normal. You can take all the time you need to research/prepare for re-installing grub until you’re confident you can do so without losing data