Ubuntu Edk2 vulnerabilities
2 known vulnerabilities affecting ubuntu/edk2.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-2486MEDIUMCVSS 6.7≥ 2024.05, < 2024.05-2ubuntu0.3≥ 2024.02, < 2024.02-2ubuntu0.32025-11-26
CVE-2025-2486 [MEDIUM] CWE-489 UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Sh
cvelistv5
CVE-2023-48733MEDIUMCVSS 6.7≥ 2024.05, < 2024.05-2ubuntu0.3≥ 2024.02, < 2024.02-2ubuntu0.32024-02-14
CVE-2023-48733 [MEDIUM] CWE-1188 CVE-2023-48733: An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
nvd