一名本地攻击者若能控制 GRUB 的配置文件,便可在启用安全启动(Secure Boot)的情况下绕过安全锁定(lockdown)限制,加载未签名的 GRUB 模块,而 GRUB 仍会继续报告安全锁定处于启用状态。 该漏洞的根源在于 GRUB 对传递给串行命令的 MMIO(内存映射 I/O)基地址缺乏充分的验证。GRUB 未检查该基地址是否确实对应一个 UART(通用异步收发传输器)设备,而非任意内存地址。这使得攻击者能够诱使 GRUB 在由攻击者控制的地址上写入非任意数据,例如以禁用后续加载模块的验证机制的方式,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet