What is UEFI-SECURE-BOOT-DB-EXPIRED?
UEFI-SECURE-BOOT-DB-EXPIRED is a high-severity hardware BIOS/UEFI problem. A Secure Boot signature in the UEFI signature database (db) has expired. Microsoft has been revoking old Secure Boot certificates as part of CVE mitigations (e.g., Black Lotus bootkit fix). After a BIOS or Windows update applies the revocation, previously trusted bootloaders or recovery media become untrusted, preventing boot. See the troubleshooting steps below for the fix.
Common Causes
- Microsoft Secure Boot certificate revocation (KB5025885)
- Outdated dual-boot Linux EFI bootloader
- Old USB recovery media with expired signatures
Step-by-Step Fix Guide
-
1
Update UEFI Secure Boot database via Windows Update
Running Windows Update applies the latest Secure Boot Allowed Signature Database (db) which recognizes current bootloaders.
-
2
Regenerate Secure Boot keys in BIOS
If dual-booting Linux, update shim and GRUB packages to signed versions.
-
3
Update or recreate bootable USB media
"Update or recreate bootable USB media" is worth trying when old USB recovery media with expired signatures turns out to be the culprit.
Commands & Diagnostics
Confirm-SecureBootUEFI
Frequently Asked Questions
The leading cause of UEFI-SECURE-BOOT-DB-EXPIRED is microsoft Secure Boot certificate revocation (KB5025885), though outdated dual-boot Linux EFI bootloader and old USB recovery media with expired signatures also show up in our reports.
The fastest fix is "Update UEFI Secure Boot database via Windows Update". Only move on to the later steps if UEFI-SECURE-BOOT-DB-EXPIRED keeps coming back.
Rated high severity — UEFI-SECURE-BOOT-DB-EXPIRED isn't immediately destructive, but recurring instances are a sign to fix it sooner rather than later.
You shouldn't need to. Work through the guide above first — a reinstall is only worth considering if none of those steps help.
Still Need Help?
Search our full database of 535+ documented PC errors for more solutions and step-by-step repair guides.
Search Error Database