CVE-2026-97876 GRUB 安全限制绕过漏洞
影响本地攻击者可绕过安全启动限制加载未签名模块
GRUB 在处理 serial 命令传入的 MMIO 基地址时缺乏充分校验,未确认该地址对应 UART 设备。攻击者可借此在可控地址写入数据,重置 grub_file_verifiers 列表,从而绕过模块签名验证。
影响范围
受影响版本范围暂无公开信息,涉及启用 Secure Boot 并使用 GRUB 的环境。
漏洞详情
漏洞属于安全限制绕过,成因是 GRUB 未验证 serial 命令的 MMIO 基地址是否为合法 UART 设备地址。攻击者可构造任意内存地址,诱使 GRUB 在受控位置写入数据,进而重置 grub_file_verifiers 列表。该列表被清空后,后续加载的 GRUB 模块不再经过签名校验,且 GRUB 仍对外报告 lockdown 处于启用状态。
利用条件与风险
利用前提是本地攻击者能够控制 GRUB 配置,并处于 Secure Boot 启动环境。实战中可加载未签名模块,破坏安全启动信任链。
修复建议
官方修复方案暂无公开信息,建议关注 GRUB 官方补丁并及时更新。临时缓解措施包括限制对 GRUB 配置的本地访问权限,并加强启动环境物理与本地安全管控。
A local attacker with control over GRUB’s configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled.
The vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command. GRUB does not validate that the base address corresponds to a UART device, rather than being an arbitrary memory address. This allows an attacker to trick GRUB into writing non-arbitrary data at an attacker-controlled address, including resetting the grub_file_verifiers list in a way that disables the subsequent verification of loaded modules.