SUSE-SU-2023:2084-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2084-1
SUSE-SU-2023:2084-1
Summary: Security update for shim
Details: This update for shim fixes the following issues: - CVE-2022-28737 was missing as reference previously. - Upgrade shim-install for bsc#1210382 After closing Leap-gap project since Leap 15.3, openSUSE Leap direct uses shim from SLE. So the ca_string is 'SUSE Linux Enterprise Secure Boot CA1', not 'openSUSE Secure Boot CA1'. It causes that the update_boot=no, so all files in /boot/efi/EFI/boot are not updated. Logic was added that is using ID field in os-release for checking Leap distro and set ca_string to 'SUSE Linux Enterprise Secure Boot CA1'. Then /boot/efi/EFI/boot/* can also be updated.
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232084-1/, https://bugzilla.suse.com/1210382, https://www.suse.com/security/cve/CVE-2022-28737
Affected packages
Package
Name: shim
Purl: pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Micro%205.3
Affected ranges
Type: ECOSYSTEM
Events:
