Bug#1148741: grub-efi: serial-MMIO secure boot bypass
Steve McIntyre
steve at einval.com
Tue Sep 22 21:53:47 BST 2026
Source: grub2
Version: 2.14-3
Severity: serious
Tags: security
X-Debbugs-Cc: debian-efi at lists.debian.org, Debian Security Team <team at security.debian.org>
This bug is already public due to uncoordinated disclosure in
https://www.openwall.com/lists/oss-security/2026/09/13/5
GRUB upstream has a fix for this bug in the latest release (2.16); I'm
working on backporting this for older releases now.
--
Steve McIntyre, Cambridge, UK. steve at einval.com
"...In the UNIX world, people tend to interpret `non-technical user'
as meaning someone who's only ever written one device driver." -- Daniel Pead
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-grub-devel/attachments/20260922/9fedbd41/attachment.sig>
More information about the Pkg-grub-devel
mailing list