logo

Secure Boot bypass risk on nearly 200,000 Linux Framework sytems

ID: 6c23440c-bf05-521b-a03b-3832bb4c1ee0

STIX ID: report--6c23440c-bf05-521b-a03b-3832bb4c1ee0

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-14

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Researchers at Eclypsium discovered that Framework shipped signed UEFI shells containing a dangerous 'mm' memory-modify command that can overwrite the Secure Boot security handler (gSecurity2), allowing attackers to disable signature verification and load persistent bootkits; approximately 200,000 Framework systems are impacted and firmware/DBX updates and temporary mitigations (physical access controls, DB key deletion) are being provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.