CVE-2026-97876: Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address

Published Oct 2, 2026
·
Updated

A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled.

The vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command. GRUB does not validate that the base address corresponds to a UART device, rather than being an arbitrary memory address. This allows an attacker to trick GRUB into writing non-arbitrary data at an attacker-controlled address, including resetting the grubfileverifiers list in a way that disables the subsequent verification of loaded modules.

Affected Software

1 affected component
GNU Project GRUB

Event History

Oct 2, 2026
CVE Published
via MITRE·10:34 AM
Data Sourced
via MITRE·10:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Exploitation requires local access and control over GRUB's configuration. It affects systems booting GRUB with Secure Boot where an attacker can supply the relevant serial-command MMIO base address.

2

What does successful exploitation allow?

An attacker can bypass GRUB lockdown restrictions and load an unsigned GRUB module while GRUB continues to report that lockdown is enabled. The described technique resets the grub_file_verifiers list, disabling verification of subsequently loaded modules.

3

What condition makes the serial command dangerous?

GRUB insufficiently validates the MMIO base address passed to its serial command. Instead of requiring the address to correspond to a UART device, it can be treated as an attacker-controlled memory address for writes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203