Bug#1148741: grub-efi: serial-MMIO secure boot bypass

Salvatore Bonaccorso carnil at debian.org
Fri Oct 2 20:28:45 BST 2026


Control: retitle -1 grub-efi: CVE-2026-97876: serial-MMIO secure boot bypass

Hi,

On Tue, Sep 22, 2026 at 09:53:47PM +0100, Steve McIntyre wrote:
> Source: grub2
> Version: 2.14-3
> Severity: serious
> Tags: security
> X-Debbugs-Cc: debian-efi at lists.debian.org, Debian Security Team <team at security.debian.org>
> 
> This bug is already public due to uncoordinated disclosure in
> 
>   https://www.openwall.com/lists/oss-security/2026/09/13/5
> 
> GRUB upstream has a fix for this bug in the latest release (2.16); I'm
> working on backporting this for older releases now.

This got https://www.cve.org/CVERecord?id=CVE-2026-97876 assigned.

Regards,
Salvatore



More information about the Pkg-grub-devel mailing list