The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.
https://bugzilla.redhat.com/show_bug.cgi?id=1329653
http://www.openwall.com/lists/oss-security/2016/09/22/4