UBUNTU-CVE-2026-21265

Source
https://ubuntu.com/security/CVE-2026-21265
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-21265.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-21265
Upstream
Published
2026-01-13T18:16:00Z
Modified
2026-01-21T18:26:31.100707Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Windows Boot Manager 10/19/2026 For more information see this CVE and Windows Secure Boot certificate expiration and CA updates.

References

Affected packages

Ubuntu:14.04:LTS
secureboot-db

Package

Name
secureboot-db
Purl
pkg:deb/ubuntu/secureboot-db@1.4~ubuntu0.14.04.1?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1
1.4~ubuntu0.14.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "secureboot-db",
            "binary_version": "1.4~ubuntu0.14.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-21265.json"
shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim@13-0ubuntu2?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.4-0ubuntu4
0.8-0ubuntu2
0.9+1474479173.6c180c6-1ubuntu1
Other
13-0ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "shim",
            "binary_version": "13-0ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-21265.json"
shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed@1.33.1~14.04.5?arch=source&distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.3
1.4
1.5
1.6
1.9
1.17~14.04.1
1.18~14.04.1
1.19~14.04.1
1.32~14.04.2
1.33.1~14.04.2
1.33.1~14.04.3
1.33.1~14.04.4
1.33.1~14.04.5

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "shim-signed",
            "binary_version": "1.33.1~14.04.5+13-0ubuntu2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-21265.json"
Ubuntu:16.04:LTS
secureboot-db

Package

Name
secureboot-db
Purl
pkg:deb/ubuntu/secureboot-db@1.4~ubuntu0.16.04.1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1
1.4~ubuntu0.16.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "secureboot-db",
            "binary_version": "1.4~ubuntu0.16.04.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-21265.json"
shim

Package

Name
shim
Purl
pkg:deb/ubuntu/shim@15.4-0ubuntu7?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.8-0ubuntu2
0.9+1474479173.6c180c6-1ubuntu1
Other
13-0ubuntu2
15+1533136590.*
15+1533136590.3beb971-0ubuntu1
15+1552672080.*
15+1552672080.a4a1fbe-0ubuntu2
15.*
15.4-0ubuntu7

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "shim",
            "binary_version": "15.4-0ubuntu7"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-21265.json"
shim-signed

Package

Name
shim-signed
Purl
pkg:deb/ubuntu/shim-signed@1.33.1~16.04.10?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.11
1.12
1.17~16.04.1
1.18~16.04.1
1.19~16.04.1
1.27~16.04.1
1.28~16.04.1
1.32~16.04.1
1.33.1~16.04.1
1.33.1~16.04.2
1.33.1~16.04.3
1.33.1~16.04.4
1.33.1~16.04.5
1.33.1~16.04.6
1.33.1~16.04.10

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "shim-signed",
            "binary_version": "1.33.1~16.04.10+15.4-0ubuntu7"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-21265.json"