CVE-2026-97876
Received Received - Intake

GRUB Lockdown Bypass via MMIO UART Configuration

Vulnerability report for CVE-2026-97876, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Canonical Ltd.

Description

A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled. The vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command. GRUB does not validate that the base address corresponds to a UART device, rather than being an arbitrary memory address. This allows an attacker to trick GRUB into writing non-arbitrary data at an attacker-controlled address, including resettingΒ the grub_file_verifiers list in a way that disables the subsequent verification of loaded modules.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gnu grub *
canonical grub2 1.215+2.14-2ubuntu1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-822 The product obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a local attacker with control over GRUB's configuration to bypass Secure Boot lockdown restrictions. The issue occurs because GRUB's serial command accepts an attacker-controlled memory-mapped I/O (MMIO) base address without validating if it points to a legitimate UART device. This lets the attacker overwrite critical security data, such as the grub_file_verifiers list, causing GRUB to disable module verification and load unsigned modules despite Secure Boot being active.

Detection Guidance

Detection requires checking if your GRUB configuration allows arbitrary MMIO base addresses for the serial command. Inspect GRUB configuration files for the 'serial' command usage with custom MMIO addresses. No direct commands detect this vulnerability as it requires manual verification of GRUB configuration and memory layout during boot.

Impact Analysis

An attacker could exploit this to execute arbitrary code within the GRUB environment by loading a malicious unsigned module. This breaks the signed-code boundary at the GRUB module layer, potentially allowing further system compromise. However, exploitation requires specific conditions like control over GRUB's boot configuration, knowledge of memory layout, and physical or administrative access to the system.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially violating integrity and access control requirements in standards like GDPR and HIPAA. It undermines secure boot mechanisms designed to ensure only trusted software runs, which may result in non-compliance with data protection and system integrity mandates.

Mitigation Strategies

Apply patches from your distribution that validate MMIO base addresses in GRUB's serial command. Disable the 'serial' command in GRUB configuration if not required. Ensure Secure Boot lockdown remains active and verify updated SBAT generation after patching.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97876. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart