{"id":"CVE-2026-97876","summary":"Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address","details":"A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled.\n\n\n\n\nThe vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command. GRUB does not validate that the base address corresponds to a UART device, rather than being an arbitrary memory address. This allows an attacker to trick GRUB into writing non-arbitrary data at an attacker-controlled address, including resetting the grub_file_verifiers list in a way that disables the subsequent verification of loaded modules.","modified":"2026-10-04T07:00:15.974099Z","published":"2026-10-02T10:34:23.314Z","database_specific":{"cna_assigner":"canonical","cwe_ids":["CWE-822"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97876.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97876.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97876"},{"type":"FIX","url":"https://gitlab.freedesktop.org/gnu-grub/grub/-/commit/26beaa3b2720fefdc4d04c1ae209b776fe6848d6"},{"type":"ARTICLE","url":"https://www.openwall.com/lists/oss-security/2026/09/13/5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.freedesktop.org/gnu-grub/grub","events":[{"introduced":"5ca9db22e8ed0dbebb2aec53722972de0680a463"},{"fixed":"26beaa3b2720fefdc4d04c1ae209b776fe6848d6"}],"database_specific":{"extracted_events":[{"introduced":"2.12"},{"fixed":"2.16"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["grub-2.16-rc2","grub-2.16-rc1","grub-2.14","grub-2.14-rc1","grub-2.12"],"database_specific":{"vanir_signatures_modified":"2026-10-04T07:00:15Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"101376851600307487605589740544843208277","length":1059},"id":"CVE-2026-97876-05d693de","signature_type":"Function","signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/ns8250.c","function":"grub_serial_ns8250_add_port"}},{"deprecated":false,"digest":{"line_hashes":["91092515920905575663549444991947473500","21685433886145471888615443402441153467","158704751980360558280009267886080320340","124202664012133925295375769962081544861","190713217913649678597287466804232160279","91025343091868647857093290058438806718","22246048253660342722511994322163815901","298288039060041159372732054602182652007","271074668893633456026502148394281948955"],"threshold":0.9},"id":"CVE-2026-97876-235a0009","signature_type":"Line","signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/ns8250-spcr.c"}},{"deprecated":false,"digest":{"line_hashes":["298134576180652224369926659253204101794","176770042599052854457000022117051535294","281020260104121347714907747069805333997","17980333401478878931697219183646636665","116035859075558654790459635318645613622","122893826083132987475788588778059779180","210573355099056627336771006487080040960","65092946917350282328317813602802405213","256286486429386793869568133856806507220","4651704342310961672323120646121099788","177044794038973646931333486710442806992"],"threshold":0.9},"id":"CVE-2026-97876-33fba7ca","signature_type":"Line","signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"include/grub/serial.h"}},{"deprecated":false,"digest":{"line_hashes":["270075507003990997917553105120051141958","86994451118961556589401896729572629802","92166417669748680375402590864338291038","284949923743725552004299924000382121520","13688526882047624103660089899421844532","62963911602314817092912998876300095920","162214940795897087354528994477161663500","171910860759981934883702112342306941879","334929450636756818717315214117536735576","315075684496127400897795492542774376563","203126658687877187686869408409380026504","216183652474856609368445731870457872063","225015037591923268370634779412744598155"],"threshold":0.9},"id":"CVE-2026-97876-360cfadb","signature_type":"Line","signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/pl011.c"}},{"deprecated":false,"digest":{"line_hashes":["137637068494831970155685355844469308323","290091997561949200313806839645701575618","318155916276573151385860789815261154693","20229759348469820675360210855310906272","308005330394737550799336599852243064815","306556560958965661783965370274945723637","258038437455591266644462240821442738605","187766784221844185222323262808008879031","261517412176705513791099047077627186794","129798130344681251962859672194866807680","163741766885859430081411876640674162818","189422407853996213582387439920073715160","15999901022532832353513363369391268107","314549650398596217986881219746290398031","102466116597031474199519154042181482155","172844176063463141935109648739314579319","188621203001611325054537340338614818187","13306904999975338496065903931449982068","176198577358073764134926197479508161802","145042299764831955793884163441716418262","89868562397560381392220091557198943226","38047453813769677650409661476823581970","122711625358212382807848265734732332262","159787083730645213440204196483038762379","140934327104899179543803073943666650741","250672174433022138617060767395593258252","204840797081161847861030759212916544841","325512338136880947256252592992583176224","104006002826351228122077107480374310212","299527374197294839686455835649840001091"],"threshold":0.9},"id":"CVE-2026-97876-36ee46d0","signature_type":"Line","signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/serial.c"}},{"digest":{"function_hash":"54767035772127154516168268615982979689","length":1555},"id":"CVE-2026-97876-410bcaba","signature_type":"Function","signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/ns8250-spcr.c","function":"grub_ns8250_spcr_init"},"deprecated":false},{"signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/ns8250.c"},"deprecated":false,"digest":{"line_hashes":["318332094371983120063122835760304274742","151885077756763625743955980137564786014","108550163920012092914364911677153435247","288450891993144514583999052812490701612","330617204214148741633295451722287654103","36273019855976195514491609576815893288","124971914173379861989616292079335186779","167214505728125969544123716823497316460","331467495598912245995091603000478635951","334929450636756818717315214117536735576","315075684496127400897795492542774376563","14873352399167979749744127424801620309","140971545279712493754954394285958422751","202611642726442102635373866322445792884","47904065162459223905377390718783482702","81949337462226138152745430447203102780","165795850347265164547124467625884730954","192335614080041437644562873783793761806","330617204214148741633295451722287654103","275344569889401547574820521978132937517","33893866687105049780179378930506412341","162214940795897087354528994477161663500","171910860759981934883702112342306941879","334929450636756818717315214117536735576","315075684496127400897795492542774376563","203126658687877187686869408409380026504","216183652474856609368445731870457872063","225015037591923268370634779412744598155"],"threshold":0.9},"id":"CVE-2026-97876-4d9111c1","signature_type":"Line"},{"source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/pl011.c","function":"grub_serial_pl011_add_mmio"},"deprecated":false,"digest":{"length":676,"function_hash":"265122578245759454484084022245214547299"},"id":"CVE-2026-97876-4e971aa2","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["47927161891337095436221749463173507721","9796520710137047400382023926915276435","38956616937640103915126838442664981803"],"threshold":0.9},"id":"CVE-2026-97876-5809ef67","signature_type":"Line","signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"include/grub/pl011.h"}},{"signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/serial.c","function":"grub_serial_find"},"deprecated":false,"digest":{"function_hash":"62336441068431096288981736956964058572","length":2487},"id":"CVE-2026-97876-713cb053","signature_type":"Function"},{"signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/serial.c","function":"grub_cmd_serial"},"deprecated":false,"digest":{"length":3378,"function_hash":"28330160908647881157352880830499677855"},"id":"CVE-2026-97876-bca841ef","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6","target":{"file":"grub-core/term/ns8250.c","function":"grub_serial_ns8250_add_mmio"},"deprecated":false,"digest":{"function_hash":"289300645627851357825887620623647118891","length":937},"id":"CVE-2026-97876-c0e84ad0"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97876.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}