Oval Definition:oval:org.opensuse.security:def:59301
Revision Date:2020-12-01Version:1
Title:Security update for shim (Moderate)
Description:

This update for shim fixes the following issues:

- Update to the unified shim binary from SUSE Linux Enterprise 15-SP1 (bsc#1168994)

This update addresses the 'BootHole' security issue (master CVE CVE-2020-10713), by disallowing binaries signed by the previous SUSE UEFI signing key from booting.

This update should only be installed after updates of grub2, the Linux kernel and (if used) Xen from July / August 2020 are applied.

Additional fixes:

+ shim-install: install MokManager to \EFI\boot to process the pending MOK request (bsc#1175626, bsc#1175656)

Family:unixClass:patch
Status:Reference(s):1021578
1027282
1041090
1042670
1073269
1073748
1078326
1078485
1081750
1084650
1086001
1087082
1087083
1089343
1104134
1111634
1111635
1124729
1124734
1126230
1128378
1132665
1136082
1136085
1145092
1149792
1153830
1155094
1157607
1159035
1159723
1159729
1161096
1162224
1162367
1162553
1162825
1164825
1165894
1166238
1168994
1170411
1171561
1171670
1171921
1171928
1171960
1171961
1171963
1172798
1172846
1173027
1173972
1174753
1174817
1174955
1175168
1175626
1175656
1177155
945401
CVE-2014-2977
CVE-2014-2978
CVE-2014-3566
CVE-2015-8079
CVE-2018-1000807
CVE-2018-1000808
CVE-2018-3639
CVE-2018-3640
CVE-2018-3646
CVE-2019-0221
CVE-2019-10208
CVE-2019-12418
CVE-2019-17563
CVE-2019-17569
CVE-2019-18348
CVE-2019-20503
CVE-2019-6974
CVE-2019-7221
CVE-2019-9213
CVE-2019-9674
CVE-2020-10713
CVE-2020-10753
CVE-2020-13844
CVE-2020-15708
CVE-2020-25637
CVE-2020-6805
CVE-2020-6806
CVE-2020-6807
CVE-2020-6811
CVE-2020-6812
CVE-2020-6814
CVE-2020-8177
CVE-2020-8492
CVE-2020-9484
SUSE-SU-2018:2331-2
SUSE-SU-2018:4063-1
SUSE-SU-2019:2159-1
SUSE-SU-2020:0717-1
SUSE-SU-2020:0854-1
SUSE-SU-2020:1498-1
SUSE-SU-2020:1524-1
SUSE-SU-2020:1732-1
SUSE-SU-2020:1748-1
SUSE-SU-2020:2628-1
SUSE-SU-2020:3095-1
SUSE-SU-2020:3263-1
Platform(s):openSUSE Leap 15.0
openSUSE Leap 15.1
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP2-ESPOS
SUSE Linux Enterprise Server 12 SP2-LTSS
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE OpenStack Cloud 8
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.0 is installed
  • AND Package Information
  • libupsclient1-2.7.4-lp150.3 is installed
  • OR nut-2.7.4-lp150.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • GraphicsMagick-1.3.29-lp151.4.3 is installed
  • OR GraphicsMagick-devel-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagick++-Q16-12-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagick++-devel-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagick-Q16-3-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagick3-config-1.3.29-lp151.4.3 is installed
  • OR libGraphicsMagickWand-Q16-2-1.3.29-lp151.4.3 is installed
  • OR perl-GraphicsMagick-1.3.29-lp151.4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-BCL is installed
  • AND ucode-intel-20180807-13.29 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_121-92_95-default-5-2 is installed
  • OR kgraft-patch-SLE12-SP2_Update_25-5-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP2-LTSS is installed
  • AND shim-15+git47-22.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • DirectFB-1.7.1-6 is installed
  • OR lib++dfb-1_7-1-1.7.1-6 is installed
  • OR libdirectfb-1_7-1-1.7.1-6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • perl-5.18.2-12.20 is installed
  • OR perl-32bit-5.18.2-12.20 is installed
  • OR perl-base-5.18.2-12.20 is installed
  • OR perl-doc-5.18.2-12.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • libssh2-1-1.4.3-20.9 is installed
  • OR libssh2-1-32bit-1.4.3-20.9 is installed
  • OR libssh2_org-1.4.3-20.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • kgraft-patch-4_4_162-94_72-default-5-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_22-5-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND axis-1.4-290.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libhogweed2-2.7.1-12 is installed
  • OR libhogweed2-32bit-2.7.1-12 is installed
  • OR libnettle4-2.7.1-12 is installed
  • OR libnettle4-32bit-2.7.1-12 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 8 is installed
  • AND Package Information
  • libvirt-3.3.0-5.46 is installed
  • OR libvirt-admin-3.3.0-5.46 is installed
  • OR libvirt-client-3.3.0-5.46 is installed
  • OR libvirt-daemon-3.3.0-5.46 is installed
  • OR libvirt-daemon-config-network-3.3.0-5.46 is installed
  • OR libvirt-daemon-config-nwfilter-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-interface-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-libxl-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-lxc-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-network-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-nodedev-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-nwfilter-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-qemu-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-secret-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-storage-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-storage-core-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-storage-disk-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-storage-iscsi-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-storage-logical-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-storage-mpath-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-storage-rbd-3.3.0-5.46 is installed
  • OR libvirt-daemon-driver-storage-scsi-3.3.0-5.46 is installed
  • OR libvirt-daemon-hooks-3.3.0-5.46 is installed
  • OR libvirt-daemon-lxc-3.3.0-5.46 is installed
  • OR libvirt-daemon-qemu-3.3.0-5.46 is installed
  • OR libvirt-daemon-xen-3.3.0-5.46 is installed
  • OR libvirt-doc-3.3.0-5.46 is installed
  • OR libvirt-libs-3.3.0-5.46 is installed
  • OR libvirt-lock-sanlock-3.3.0-5.46 is installed
  • OR libvirt-nss-3.3.0-5.46 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND Package Information
  • libX11-1.6.2-12.12 is installed
  • OR libX11-6-1.6.2-12.12 is installed
  • OR libX11-6-32bit-1.6.2-12.12 is installed
  • OR libX11-data-1.6.2-12.12 is installed
  • OR libX11-xcb1-1.6.2-12.12 is installed
  • OR libX11-xcb1-32bit-1.6.2-12.12 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • tomcat-8.0.53-29.27 is installed
  • OR tomcat-admin-webapps-8.0.53-29.27 is installed
  • OR tomcat-docs-webapp-8.0.53-29.27 is installed
  • OR tomcat-el-3_0-api-8.0.53-29.27 is installed
  • OR tomcat-javadoc-8.0.53-29.27 is installed
  • OR tomcat-jsp-2_3-api-8.0.53-29.27 is installed
  • OR tomcat-lib-8.0.53-29.27 is installed
  • OR tomcat-servlet-3_1-api-8.0.53-29.27 is installed
  • OR tomcat-webapps-8.0.53-29.27 is installed
  • BACK