A Canonical-signed GRUB can execute unsigned native code while lockdown still reports enabled.
A lockdown-permitted serial command can erase the bootloader’s authoritative verifier list.
Affects
Ubuntu's Canonical-signed GNU GRUB EFI bootloader for x86-64 Linux systems, confirmed in an enforcing QEMU/OVMF Secure Boot VM.
What it enables
Unsigned native GRUB module execution inside a signed, lockdown-active bootloader
Control a GRUB configuration source that the target accepts without authenticating the configuration and select that boot path.→↓Boot the hash-pinned Canonical-signed gcdx64.efi image through an admitted shim/SBAT path.→↓Use the lockdown-available gdbinfo command to verify the expected image placement.→↓Configure the serial command with a 64-bit MMIO base targeting grub_file_verifiers.→↓Trigger serial input initialization, whose fixed UART stores clear the verifier-list head.→↓Load and execute an unsigned native GRUB module while lockdown continues to report y.
Why this matters
The result is unsigned native execution inside a signed bootloader whose lockdown state still appears intact.
Detail, proof-of-concept code and 6 sources
Required access
Control of a GRUB configuration source accepted without configuration authentication, ability to select that boot path, and knowledge of the exact loaded-image placement; demonstrated in QEMU/OVMF
The attacker must control a GRUB configuration source the target accepts without authenticating it, select that boot path, and know the loaded-image placement. An attacker-selected serial MMIO base then redirects fixed UART initialization stores onto grub_file_verifiers and clears the list head.
The public repository supplies the configuration, marker-module generator, hashes, controls and console evidence for three enforcing QEMU/OVMF runs.
There is no patch. We do not have physical-hardware or cross-distribution reproduction, and no vendor acknowledgement is held.
Evidence
Reporter reproduced unsigned native-module execution in three enforcing QEMU/OVMF runs against a hash-pinned signed imagePublic repository contains the exact GRUB configuration, marker-module generator, hashes, controls, and console evidencePhysical-hardware reproductionCross-build or cross-distribution reproductionVendor acknowledgement or shipped fix
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.