47
GNU GRUB 2.14: serial-MMIO lockdown bypass in Canonical-signed gcdx64.efi
Canonical-signed GRUB2 serial command accepts arbitrary MMIO addresses, letting local attackers with grub.cfg control bypass Secure Boot lockdown.
A vulnerability in Canonical's grub-efi-amd64-signed (gcdx64.efi, GRUB 2.14) exposes a serial command that accepts a caller-supplied 64-bit MMIO base address. The lockdown path does not restrict this command even when lockdown=y under UEFI Secure Boot, and the serial implementation does not validate that the requested register span belongs to a real UART rather than ordinary RAM. A local attacker with control of GRUB's boot configuration can abuse this to bypass the Secure Boot lockdown.
55
60
42
57
42
42
60
42
60
60
57
57
47
42
57
42
42
42
60
42
42
60
47
42
42
42
60
57
60
57
60
42
42