important · Boot chain
A QEMU VM console operator can replace Secure Boot trust without physical-presence authorization.
Affects
QEMU virtual machines using the host-backed uefi-vars service with compatible OVMF firmware for Secure Boot
Access to the virtual firmware console is enough: OVMF permits CustomMode without the expected physical-presence check, then allows unrestricted Secure Boot-variable updates.
Detail and 3 sources
That permits removal or replacement of the VM's existing boot trust without QEMU-host access.
An upstream patch changes the default, but QEMU 11.1.1 predates it and a fixed release was not established.