{"id":"SUSE-SU-2023:2084-1","summary":"Security update for shim","details":"This update for shim fixes the following issues:\n\n- CVE-2022-28737 was missing as reference previously.\n\n- Upgrade shim-install for bsc#1210382\n\n  After closing Leap-gap project since Leap 15.3, openSUSE Leap direct\n  uses shim from SLE. So the ca_string is 'SUSE Linux Enterprise Secure Boot\n  CA1', not 'openSUSE Secure Boot CA1'. It causes that the update_boot=no,\n  so all files in /boot/efi/EFI/boot are not updated.\n\n  Logic was added that is using ID field in os-release for\n  checking Leap distro and set ca_string to 'SUSE Linux Enterprise Secure\n  Boot CA1'. Then /boot/efi/EFI/boot/* can also be updated.\n","modified":"2026-03-11T07:23:54.964680Z","published":"2023-05-02T11:32:01Z","related":["CVE-2022-28737"],"upstream":["CVE-2022-28737"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232084-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1210382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-28737"}],"affected":[{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP4","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise Real Time 15 SP3","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise Server 15 SP3-LTSS","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP3","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Manager Proxy 4.2","purl":"pkg:rpm/suse/shim&distro=SUSE%20Manager%20Proxy%204.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Manager Server 4.2","purl":"pkg:rpm/suse/shim&distro=SUSE%20Manager%20Server%204.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise Micro 5.1","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Micro%205.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/shim&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"SUSE:Enterprise Storage 7.1","purl":"pkg:rpm/suse/shim&distro=SUSE%20Enterprise%20Storage%207.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"openSUSE:Leap Micro 5.3","purl":"pkg:rpm/opensuse/shim&distro=openSUSE%20Leap%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}},{"package":{"name":"shim","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/shim&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"15.7-150300.4.16.1"}]}],"ecosystem_specific":{"binaries":[{"shim":"15.7-150300.4.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2084-1.json"}}],"schema_version":"1.7.5"}