CVE-2026-97876

Source
https://cve.org/CVERecord?id=CVE-2026-97876
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97876.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-97876
Downstream
Published
2026-10-02T10:34:23Z
Modified
2026-10-04T07:00:15Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bypass of GRUB lockdown restriction in Secure Boot mode via serial command MMIO base address
Details

A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB continues to report lockdown is enabled.

The vulnerability is caused by insufficient validation of the MMIO base address passed to the GRUB serial command. GRUB does not validate that the base address corresponds to a UART device, rather than being an arbitrary memory address. This allows an attacker to trick GRUB into writing non-arbitrary data at an attacker-controlled address, including resettingĀ the grub_file_verifiers list in a way that disables the subsequent verification of loaded modules.

Database specific
{
    "cna_assigner":  "canonical",
    "cwe_ids":  [
        "CWE-822"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/97xxx/CVE-2026-97876.json"
}
References

Affected packages

Git / gitlab.freedesktop.org/gnu-grub/grub

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/gnu-grub/grub
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.12"
        },
        {
            "fixed":  "2.16"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

grub-2.*
grub-2.12
grub-2.14
grub-2.14-rc1
grub-2.16-rc1
grub-2.16-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-97876.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "101376851600307487605589740544843208277",
            "length":  1059
        },
        "id":  "CVE-2026-97876-05d693de",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/ns8250.c",
            "function":  "grub_serial_ns8250_add_port"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "91092515920905575663549444991947473500",
                "21685433886145471888615443402441153467",
                "158704751980360558280009267886080320340",
                "124202664012133925295375769962081544861",
                "190713217913649678597287466804232160279",
                "91025343091868647857093290058438806718",
                "22246048253660342722511994322163815901",
                "298288039060041159372732054602182652007",
                "271074668893633456026502148394281948955"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97876-235a0009",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/ns8250-spcr.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "298134576180652224369926659253204101794",
                "176770042599052854457000022117051535294",
                "281020260104121347714907747069805333997",
                "17980333401478878931697219183646636665",
                "116035859075558654790459635318645613622",
                "122893826083132987475788588778059779180",
                "210573355099056627336771006487080040960",
                "65092946917350282328317813602802405213",
                "256286486429386793869568133856806507220",
                "4651704342310961672323120646121099788",
                "177044794038973646931333486710442806992"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97876-33fba7ca",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "include/grub/serial.h"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "270075507003990997917553105120051141958",
                "86994451118961556589401896729572629802",
                "92166417669748680375402590864338291038",
                "284949923743725552004299924000382121520",
                "13688526882047624103660089899421844532",
                "62963911602314817092912998876300095920",
                "162214940795897087354528994477161663500",
                "171910860759981934883702112342306941879",
                "334929450636756818717315214117536735576",
                "315075684496127400897795492542774376563",
                "203126658687877187686869408409380026504",
                "216183652474856609368445731870457872063",
                "225015037591923268370634779412744598155"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97876-360cfadb",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/pl011.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "137637068494831970155685355844469308323",
                "290091997561949200313806839645701575618",
                "318155916276573151385860789815261154693",
                "20229759348469820675360210855310906272",
                "308005330394737550799336599852243064815",
                "306556560958965661783965370274945723637",
                "258038437455591266644462240821442738605",
                "187766784221844185222323262808008879031",
                "261517412176705513791099047077627186794",
                "129798130344681251962859672194866807680",
                "163741766885859430081411876640674162818",
                "189422407853996213582387439920073715160",
                "15999901022532832353513363369391268107",
                "314549650398596217986881219746290398031",
                "102466116597031474199519154042181482155",
                "172844176063463141935109648739314579319",
                "188621203001611325054537340338614818187",
                "13306904999975338496065903931449982068",
                "176198577358073764134926197479508161802",
                "145042299764831955793884163441716418262",
                "89868562397560381392220091557198943226",
                "38047453813769677650409661476823581970",
                "122711625358212382807848265734732332262",
                "159787083730645213440204196483038762379",
                "140934327104899179543803073943666650741",
                "250672174433022138617060767395593258252",
                "204840797081161847861030759212916544841",
                "325512338136880947256252592992583176224",
                "104006002826351228122077107480374310212",
                "299527374197294839686455835649840001091"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97876-36ee46d0",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/serial.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "54767035772127154516168268615982979689",
            "length":  1555
        },
        "id":  "CVE-2026-97876-410bcaba",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/ns8250-spcr.c",
            "function":  "grub_ns8250_spcr_init"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "318332094371983120063122835760304274742",
                "151885077756763625743955980137564786014",
                "108550163920012092914364911677153435247",
                "288450891993144514583999052812490701612",
                "330617204214148741633295451722287654103",
                "36273019855976195514491609576815893288",
                "124971914173379861989616292079335186779",
                "167214505728125969544123716823497316460",
                "331467495598912245995091603000478635951",
                "334929450636756818717315214117536735576",
                "315075684496127400897795492542774376563",
                "14873352399167979749744127424801620309",
                "140971545279712493754954394285958422751",
                "202611642726442102635373866322445792884",
                "47904065162459223905377390718783482702",
                "81949337462226138152745430447203102780",
                "165795850347265164547124467625884730954",
                "192335614080041437644562873783793761806",
                "330617204214148741633295451722287654103",
                "275344569889401547574820521978132937517",
                "33893866687105049780179378930506412341",
                "162214940795897087354528994477161663500",
                "171910860759981934883702112342306941879",
                "334929450636756818717315214117536735576",
                "315075684496127400897795492542774376563",
                "203126658687877187686869408409380026504",
                "216183652474856609368445731870457872063",
                "225015037591923268370634779412744598155"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97876-4d9111c1",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/ns8250.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "265122578245759454484084022245214547299",
            "length":  676
        },
        "id":  "CVE-2026-97876-4e971aa2",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/pl011.c",
            "function":  "grub_serial_pl011_add_mmio"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "47927161891337095436221749463173507721",
                "9796520710137047400382023926915276435",
                "38956616937640103915126838442664981803"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-97876-5809ef67",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "include/grub/pl011.h"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "62336441068431096288981736956964058572",
            "length":  2487
        },
        "id":  "CVE-2026-97876-713cb053",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/serial.c",
            "function":  "grub_serial_find"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "28330160908647881157352880830499677855",
            "length":  3378
        },
        "id":  "CVE-2026-97876-bca841ef",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/serial.c",
            "function":  "grub_cmd_serial"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "289300645627851357825887620623647118891",
            "length":  937
        },
        "id":  "CVE-2026-97876-c0e84ad0",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://gitlab.freedesktop.org/gnu-grub/grub@26beaa3b2720fefdc4d04c1ae209b776fe6848d6",
        "target":  {
            "file":  "grub-core/term/ns8250.c",
            "function":  "grub_serial_ns8250_add_mmio"
        }
    }
]
vanir_signatures_modified
"2026-10-04T07:00:15Z"