An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
2024-02-14T22:15:47.530
2025-08-26T17:19:29.193
Analyzed
CVSSv3.1: 6.7 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | canonical | lxd | < 5.21.0 | Yes |
| Application | tianocore | edk2 | ≤ 2023.11-8 | Yes |