GRUB Privilege Escalation via Bypass of Secure Boot Lockdown
CVE-2026-97876 Published on October 2, 2026
Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address
A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled.
The vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command. GRUB does not validate that the base address corresponds to a UART device, rather than being an arbitrary memory address. This allows an attacker to trick GRUB into writing non-arbitrary data at an attacker-controlled address, including resetting the grub_file_verifiers list in a way that disables the subsequent verification of loaded modules.
Vulnerability Analysis
CVE-2026-97876 is exploitable with local system access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Untrusted Pointer Dereference
The program obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Products Associated with CVE-2026-97876
Want to know whenever a new CVE is published for GNU Grub2? stack.watch will email you.
Affected Versions
GNU grub2:- Version 2.12 and below 2.16 is affected.