CVE-2023-48733: Canonical Lxd
Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Affected products
- Canonical Lxd: version 5.0 only; version 5.21 only
- Debian Debian Linux: version 10.0 only
- Tianocore EDK2: up to and including 2023.11-8
Published 2024-02-14. Last modified 2026-06-17.