Skip to finding
important · Boot chain

A QEMU VM console operator can replace Secure Boot trust without physical-presence authorization.

Affects

QEMU virtual machines using the host-backed uefi-vars service with compatible OVMF firmware for Secure Boot

Access to the virtual firmware console is enough: OVMF permits CustomMode without the expected physical-presence check, then allows unrestricted Secure Boot-variable updates.

Detail and 3 sources

That permits removal or replacement of the VM's existing boot trust without QEMU-host access.

An upstream patch changes the default, but QEMU 11.1.1 predates it and a fixed release was not established.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026