Grub2: grub allow access to encrypted device through cli once root device is unlocked via tpm (CVE-2025-4382) | HOL Guard CVE