Bug#1148741: grub-efi: serial-MMIO secure boot bypass
Salvatore Bonaccorso
carnil at debian.org
Fri Oct 2 20:28:45 BST 2026
Control: retitle -1 grub-efi: CVE-2026-97876: serial-MMIO secure boot bypass
Hi,
On Tue, Sep 22, 2026 at 09:53:47PM +0100, Steve McIntyre wrote:
> Source: grub2
> Version: 2.14-3
> Severity: serious
> Tags: security
> X-Debbugs-Cc: debian-efi at lists.debian.org, Debian Security Team <team at security.debian.org>
>
> This bug is already public due to uncoordinated disclosure in
>
> https://www.openwall.com/lists/oss-security/2026/09/13/5
>
> GRUB upstream has a fix for this bug in the latest release (2.16); I'm
> working on backporting this for older releases now.
This got https://www.cve.org/CVERecord?id=CVE-2026-97876 assigned.
Regards,
Salvatore
More information about the Pkg-grub-devel
mailing list