Impact
A local attacker who can modify GRUB’s configuration can bypass the Secure Boot lockdown restriction by supplying an invalid MMIO base address to the serial command. The lack of validation lets GRUB write to an attacker‑controlled memory location, resetting the grub_file_verifiers list and disabling verification of subsequently loaded modules. This effectively allows the attacker to load and execute unsigned GRUB modules during the boot process, providing a path to execute arbitrary code with full system privileges. The weakness is identified as CWE‑822.
Affected Systems
The vulnerability affects GNU Grub2. No specific version range is enumerated, but any instance that includes the serial command while booting in Secure Boot mode is susceptible. The documented fix is in commit 26beaa3b from the GNU Grub project.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium risk level, and the EPSS score is unavailable. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access to modify GRUB configuration before the system boots, making the attack likely limited to scenarios where an attacker has physical or otherwise privileged access to the boot media. To succeed, the attacker must supply an MMIO base address that does not correspond to a UART device, which suffices to disable module verification and enable unsigned module execution.
OpenCVE Enrichment