CVE-2025-2486

Source
https://cve.org/CVERecord?id=CVE-2025-2486
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-2486.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-2486
Downstream
Published
2025-11-26T17:33:17.506Z
Modified
2026-07-15T01:49:09.461419475Z
Severity
  • 3.7 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:U CVSS Calculator
Summary
UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu
Details

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.

Database specific
{
    "cna_assigner": "canonical",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2486.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2024.05"
                },
                {
                    "fixed": "2024.05-2ubuntu0.3"
                },
                {
                    "introduced": "2024.02"
                },
                {
                    "fixed": "2024.02-2ubuntu0.3"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cwe_ids": [
        "CWE-489"
    ]
}
References

Affected packages

Git / github.com/tianocore/edk2

Affected ranges

Type
GIT
Repo
https://github.com/tianocore/edk2
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:tianocore:edk2:202402*:*:*:*:*:*:*:*",
        "cpe:2.3:a:tianocore:edk2:202405:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "202402*"
        },
        {
            "last_affected": "202402*"
        },
        {
            "introduced": "202405"
        },
        {
            "last_affected": "202405"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

Other
202402*
202405
edk2-stable202402
edk2-stable202405

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-2486.json"