Back

HIGH

grub2: acpi command allows privileged user to load crafted ACPI tables when Secure Boot is enabled

Published Mar 3, 2021

Description

A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is further loaded and executed by the kernel, defeating its Secure Boot lockdown and allowing the attacker to load unsigned code. The highest threat from this vulnerability is to data confidentiality and integrity, as well as system availability.

Affected products

Remediation

Red Hat statement

For a successful attack to occur, the attacker needs to triage the environment to determine where the lockdown variable symbol is placed in memory when the kernel is loaded. Then the SSDT table needs to be written accordingly into this memory position and the grub.cfg file needs to be changed to load the table during the boot time.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 3, 2021
Updated Aug 4, 2024
Reserved Jun 17, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 2, 2021