CVE-2025-2486 Affecting edk2 package, versions <2025.02-3ubuntu1


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.01% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2504-EDK2-9892754
  • published29 Apr 2025
  • disclosed26 Nov 2025

Introduced: 29 Apr 2025

CVE-2025-2486  (opens in a new tab)

How to fix?

Upgrade Ubuntu:25.04 edk2 to version 2025.02-3ubuntu1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream edk2 package and not the edk2 package as distributed by Ubuntu. See How to fix? for Ubuntu:25.04 relevant fixed versions and status.

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be sufficient to enforce Secure Boot restrictions. This is an additional repair on top of the incomplete fix for CVE-2023-48733.