🔐 CVE Alert

CVE-2026-97876

MEDIUM 6.4

Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled. The vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command. GRUB does not validate that the base address corresponds to a UART device, rather than being an arbitrary memory address. This allows an attacker to trick GRUB into writing non-arbitrary data at an attacker-controlled address, including resetting the grub_file_verifiers list in a way that disables the subsequent verification of loaded modules.

CWE CWE-822
Vendor gnu
Product grub2
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for gnu grub2

Be the first to know when new medium vulnerabilities affecting gnu grub2 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

GNU / grub2
2.12 < 2.16

References

NVD ↗ CVE.org ↗ EPSS Data ↗
openwall.com: https://www.openwall.com/lists/oss-security/2026/09/13/5 gitlab.freedesktop.org: https://gitlab.freedesktop.org/gnu-grub/grub/-/commit/26beaa3b2720fefdc4d04c1ae209b776fe6848d6

Credits

🔍 Leïth Essid Andrew Hamilton