Researchers Hector Marco and Ismael Ripoll have found that the Grub2 authentication could be easily defeated by hitting backspace 28 times. The researchers from the University of Valencias Cybersecurity research group have released a fix that is available here. The integer underflow vulnerability is in the code of Grub since 2009 and resides in the grub_password_get() function. An attacker can exploit the rescue shell to load another environment that allows him to fully compromise the machine, for example by installing a rootkit.”]
Source: https://securityaffairs.co/wordpress/42847/hacking/linux-grub2-hacking.html

