CVE-2023-48733: Canonical Lxd

Medium severity, CVSS 6.7. EPSS: 0.3% chance of exploitation in the next 30 days.

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

Affected products

  • Canonical Lxd: version 5.0 only; version 5.21 only
  • Debian Debian Linux: version 10.0 only
  • Tianocore EDK2: up to and including 2023.11-8

Published 2024-02-14. Last modified 2026-06-17.