An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
| Software | From | Fixed in |
|---|---|---|
| canonical / lxd | 5.0-candidate | 5.0-candidate.x |
| canonical / lxd | 5.21-candidate | 5.21-candidate.x |
| canonical / lxd | 5.21-edge | 5.21-edge.x |
| tianocore / edk2 | - | 2023.11-8.x |
| debian / debian_linux | 10.0 | 10.0.x |