CVE-2025-2486: UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.
Other sources
UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
— Microsoft
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2486?
CVE-2025-2486 has been classified as a high severity vulnerability due to its potential to bypass Secure Boot constraints.
How do I fix CVE-2025-2486?
To fix CVE-2025-2486, upgrade to versions 2024.05-2ubuntu0.3 or 2024.02-2ubuntu0.3 of the Ubuntu edk2 UEFI firmware packages.
What does CVE-2025-2486 affect?
CVE-2025-2486 affects the Ubuntu edk2 UEFI firmware packages that allow UEFI Shell access in Secure Boot environments.
Can CVE-2025-2486 be exploited remotely?
CVE-2025-2486 does not specify remote exploitation, but it presents a risk in devices using affected versions with Secure Boot enabled.
What is the impact of CVE-2025-2486?
The impact of CVE-2025-2486 could lead to unauthorized access and potential compromise of secure environments by bypassing Secure Boot.