Skip to finding
§
High
Boot chain
Confirmed

A Canonical-signed GRUB can execute unsigned native code while lockdown still reports enabled.

A lockdown-permitted serial command can erase the bootloader’s authoritative verifier list.

Affects

Ubuntu's Canonical-signed GNU GRUB EFI bootloader for x86-64 Linux systems, confirmed in an enforcing QEMU/OVMF Secure Boot VM.

What it enables

Unsigned native GRUB module execution inside a signed, lockdown-active bootloader

Control a GRUB configuration source that the target accepts without authenticating the configuration and select that boot path.→↓Boot the hash-pinned Canonical-signed gcdx64.efi image through an admitted shim/SBAT path.→↓Use the lockdown-available gdbinfo command to verify the expected image placement.→↓Configure the serial command with a 64-bit MMIO base targeting grub_file_verifiers.→↓Trigger serial input initialization, whose fixed UART stores clear the verifier-list head.→↓Load and execute an unsigned native GRUB module while lockdown continues to report y.
Why this matters

The result is unsigned native execution inside a signed bootloader whose lockdown state still appears intact.

Detail, proof-of-concept code and 6 sources
Required access

Control of a GRUB configuration source accepted without configuration authentication, ability to select that boot path, and knowledge of the exact loaded-image placement; demonstrated in QEMU/OVMF

Affected versions

Ubuntu grub-efi-amd64-signed 1.215+2.14-2ubuntu1, gcdx64.efi.signed SHA-256 dc505a15c1bd97878eede212a052a1bfb2f610176a5401a3679877c536fdcd62

Proof of concept

Public exploit code →

The attacker must control a GRUB configuration source the target accepts without authenticating it, select that boot path, and know the loaded-image placement. An attacker-selected serial MMIO base then redirects fixed UART initialization stores onto grub_file_verifiers and clears the list head.

The public repository supplies the configuration, marker-module generator, hashes, controls and console evidence for three enforcing QEMU/OVMF runs.

There is no patch. We do not have physical-hardware or cross-distribution reproduction, and no vendor acknowledgement is held.

Evidence
Reporter reproduced unsigned native-module execution in three enforcing QEMU/OVMF runs against a hash-pinned signed imagePublic repository contains the exact GRUB configuration, marker-module generator, hashes, controls, and console evidencePhysical-hardware reproductionCross-build or cross-distribution reproductionVendor acknowledgement or shipped fix
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026