Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97876— Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address

Quick assessment

Affected
GNU grub2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

一名本地攻击者若能控制 GRUB 的配置文件,便可在启用安全启动(Secure Boot)的情况下绕过安全锁定(lockdown)限制,加载未签名的 GRUB 模块,而 GRUB 仍会继续报告安全锁定处于启用状态。 该漏洞的根源在于 GRUB 对传递给串行命令的 MMIO(内存映射 I/O)基地址缺乏充分的验证。GRUB 未检查该基地址是否确实对应一个 UART(通用异步收发传输器)设备,而非任意内存地址。这使得攻击者能够诱使 GRUB 在由攻击者控制的地址上写入非任意数据,例如以禁用后续加载模块的验证机制的方式,

CVSS 6.4 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
GNU grub2 2.12< 2.16 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97876

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address
Source: CVE Program / CVE List V5
Vulnerability Description
A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled. The vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command. GRUB does not validate that the base address corresponds to a UART device, rather than being an arbitrary memory address. This allows an attacker to trick GRUB into writing non-arbitrary data at an attacker-controlled address, including resetting the grub_file_verifiers list in a way that disables the subsequent verification of loaded modules.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
非可信指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GNU grub2 2.12 ~ 2.16 -

II. Public POCs for CVE-2026-97876

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97876

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97876 (1)

Mailing List Discussions for CVE-2026-97876 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-97876

No comments yet


Leave a comment