https://seclists.org/oss-sec/2024/q1/134: Secure Boot bypass in EDK2 based Virtual Machine firmware
Published Feb 14, 2024
·Updated
Affected Software
4 affected components
Ubuntu edk2
OVMF OVMF
AAVMF AAVMF
LXD LXD
Frequently Asked Questions
1
What is the severity of CVE-2024-XXXX?
The severity of CVE-2024-XXXX is high due to its potential to bypass Secure Boot mechanisms.
2
How do I fix CVE-2024-XXXX?
To fix CVE-2024-XXXX, update to the latest version of the EDK2 firmware that addresses the insecure default configurations.
3
What systems are affected by CVE-2024-XXXX?
CVE-2024-XXXX affects systems using EDK2 based firmware, including Ubuntu's OVMF and AAVMF, as well as LXD.
4
What are the potential risks of CVE-2024-XXXX?
The potential risks of CVE-2024-XXXX include unauthorized access and control over virtual machines by bypassing Secure Boot.
5
When was CVE-2024-XXXX published?
CVE-2024-XXXX was published on February 14, 2024.