Bug? absolutely. Critical? not so sure.
Bug? absolutely. Critical? not so sure.
Why that ever was considered a valid security approach is over me, as there is an entire gallery of vulnerabilities like this one. It also completely ignores the elephant in the room called Windows.
Example of this type of thinking: https://lkml.org/lkml/2018/4/3/767
Note that despite Linus' reticences, in a lot of distros integrity mode is indeed enabled when you boot with Secure Boot on. Likely because of MS politics and distros wanting an MS UEFI signature being forced to "go through the hoops" as explained in that thread. As a result enabling Secure Boot usually cripples your distro, preventing you from e.g. hibernating.
in sum, it's critical, because the attack vector is beyond just http.