CVE Database
/

CVE-2025-2486

Back to search

CVE-2025-2486

Published: Nov 26, 2025

Modified: Nov 26, 2025

PUBLISHED

Description

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.

VendorProductVersions

Ubuntu

edk2

affected
2024.05 - < 2024.05-2ubuntu0.3
affected
2024.02 - < 2024.02-2ubuntu0.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now