gpp_maybe Security update for shim
SUSE-SLE-Micro-5.4-2023-2084


This update for shim fixes the following issues: - CVE-2022-28737 was missing as reference previously. - Upgrade shim-install for bsc#1210382 After closing Leap-gap project since Leap 15.3, openSUSE Leap direct uses shim from SLE. So the ca_string is 'SUSE Linux Enterprise Secure Boot CA1', not 'openSUSE Secure Boot CA1'. It causes that the update_boot=no, so all files in /boot/efi/EFI/boot are not updated. Logic was added that is using ID field in os-release for checking Leap distro and set ca_string to 'SUSE Linux Enterprise Secure Boot CA1'. Then /boot/efi/EFI/boot/* can also be updated.

  • Release Date
    May 2 2023
  • References
    Bugzilla: 1210382
    CVEs: CVE-2022-28737
  • Type
    security
  • Severity
    important

cloud_download Downloads

SUSE Linux Enterprise Micro 5.4 aarch64
  • Packages
    shim
    UEFI shim loader
    15.7-150300.4.16.1 lock rpm lock src
SUSE Linux Enterprise Micro 5.4 x86_64
  • Packages
    shim
    UEFI shim loader
    15.7-150300.4.16.1 lock rpm lock src