Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-49721

Опубликовано: 14 фев. 2024
Источник: debian

Описание

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lxdnot-affectedpackage
incusnot-affectedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2024/02/14/4

  • https://bugs.launchpad.net/ubuntu/+source/lxd/+bug/2040139

Связанные уязвимости

CVSS3: 6.7
ubuntu
почти 2 года назад

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

CVSS3: 6.7
nvd
почти 2 года назад

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

CVSS3: 6.7
github
почти 2 года назад

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.