[1] https://github.com/torvalds/linux/blob/master/Documentation/...
[2] https://github.com/torvalds/linux/blob/8afda8b26d01ee26a60ef...
I would look at the wonders of UEFI.
It's also possible to bridge from a higher level to a lower level, typically when flashing your BIOS, chances are you're doing it from the OS (it's usually possible to do it at a lower level though).
In this case it looks like a kernel module that does exactly that has been enabled before being ready from prime time. Woups.
The BIOS is not to be messed with by user software or the OS. It should be signed and only changed by the manufacturer tool to update it.
From never-fixed bugs in manufacturer's firmware to setting up things to happen on the next boot, there are innumerable reasons to write to the BIOS from a higher level.
Made the news some years back I think.
This problem is about breaking the BIOS in some way, something that you should not be able to do.
To learn the real story, go and read https://news.ycombinator.com/item?id=11152880 where you will find Matthew Garrett xyrself participating in the discussion.
[1]: https://www.phoronix.com/scan.php?page=news_item&px=UEFI-rm-...
https://www.phoronix.com/scan.php?page=news_item&px=UEFI-rm-...
:(