256
Found in the wild: The world’s first unkillable UEFI bootkit for Linux
(arstechnica.com)
This is a most excellent place for technology news and articles.
The Fedora doc on this is a bit old but it's still mostly the same:
The implementation of secure boot is still questionable to this day, but it is understandable that it doesn't always play nice with Linux. I do believe you can use hibernate now as long as you have an encrypted swap (LUKS).
I can definitely see the pain if you happen to be a kernel dev or use linux on any SBC with IO ports you want to mess with in userspace and not make en entire overkill kernel module for.