CVE-2023-49721: Canonical Lxd

Medium severity, CVSS 6.7. EPSS: 0.2% chance of exploitation in the next 30 days.

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Affected products

  • Canonical Lxd: from 5.0.0, before 5.21.0 (fixed in 5.21.0)
  • Tianocore EDK2: up to and including 2023.11-8

Published 2024-02-14. Last modified 2026-06-17.