Oval Definition:oval:org.opensuse.security:def:64147
Revision Date:2020-12-01Version:1
Title:Security update for shim (Moderate)
Description:

This update for shim fixes the following issues:

- Update to the unified shim binary from SUSE Linux Enterprise 15-SP1 (bsc#1168994)

This update addresses the 'BootHole' security issue (master CVE CVE-2020-10713), by disallowing binaries signed by the previous SUSE UEFI signing key from booting.

This update should only be installed after updates of grub2, the Linux kernel and (if used) Xen from July / August 2020 are applied.

Additional fixes:

+ shim-install: install MokManager to \EFI\boot to process the pending MOK request (bsc#1175626, bsc#1175656)

Family:unixClass:patch
Status:Reference(s):1081947
1082293
1085196
1106214
1115375
1121197
1122417
1125886
1127701
1135534
1135708
1140461
1141113
1141780
1141781
1141782
1141783
1141784
1141785
1141787
1141788
1141789
1155321
1156318
1161883
1163889
1168994
1170446
1173592
1173594
1174458
1175239
1175626
1175656
1178971
353876
CVE-2013-6473
CVE-2013-6474
CVE-2013-6475
CVE-2013-6476
CVE-2014-2707
CVE-2014-4336
CVE-2014-4337
CVE-2014-4338
CVE-2015-2265
CVE-2015-3258
CVE-2015-3279
CVE-2015-8327
CVE-2015-8560
CVE-2019-2745
CVE-2019-2762
CVE-2019-2766
CVE-2019-2769
CVE-2019-2786
CVE-2019-2816
CVE-2019-2818
CVE-2019-2821
CVE-2019-7317
CVE-2019-8551
CVE-2019-8558
CVE-2019-8559
CVE-2019-8563
CVE-2019-8625
CVE-2019-8674
CVE-2019-8681
CVE-2019-8684
CVE-2019-8686
CVE-2019-8687
CVE-2019-8688
CVE-2019-8689
CVE-2019-8690
CVE-2019-8707
CVE-2019-8710
CVE-2019-8719
CVE-2019-8720
CVE-2019-8726
CVE-2019-8733
CVE-2019-8735
CVE-2019-8743
CVE-2019-8763
CVE-2019-8764
CVE-2019-8765
CVE-2019-8766
CVE-2019-8768
CVE-2019-8769
CVE-2019-8771
CVE-2019-8782
CVE-2019-8783
CVE-2019-8808
CVE-2019-8811
CVE-2019-8812
CVE-2019-8813
CVE-2019-8814
CVE-2019-8815
CVE-2019-8816
CVE-2019-8819
CVE-2019-8820
CVE-2019-8821
CVE-2019-8822
CVE-2019-8823
CVE-2020-10713
CVE-2020-14339
CVE-2020-14363
CVE-2020-8695
CVE-2020-8696
CVE-2020-8698
CVE-2020-8955
openSUSE-SU-2019:1916-1
openSUSE-SU-2019:2121-1
openSUSE-SU-2019:2591-1
openSUSE-SU-2020:0248-1
openSUSE-SU-2020:1368-1
openSUSE-SU-2020:1455-1
SUSE-SU-2020:2627-1
SUSE-SU-2020:3514-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • java-11-openjdk-11.0.4.0-lp151.3.6 is installed
  • OR java-11-openjdk-accessibility-11.0.4.0-lp151.3.6 is installed
  • OR java-11-openjdk-demo-11.0.4.0-lp151.3.6 is installed
  • OR java-11-openjdk-devel-11.0.4.0-lp151.3.6 is installed
  • OR java-11-openjdk-headless-11.0.4.0-lp151.3.6 is installed
  • OR java-11-openjdk-javadoc-11.0.4.0-lp151.3.6 is installed
  • OR java-11-openjdk-jmods-11.0.4.0-lp151.3.6 is installed
  • OR java-11-openjdk-src-11.0.4.0-lp151.3.6 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libvirt-6.0.0-lp152.9.3 is installed
  • OR libvirt-admin-6.0.0-lp152.9.3 is installed
  • OR libvirt-bash-completion-6.0.0-lp152.9.3 is installed
  • OR libvirt-client-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-config-network-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-config-nwfilter-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-interface-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-libxl-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-lxc-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-network-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-nodedev-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-nwfilter-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-qemu-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-secret-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-core-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-disk-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-gluster-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-iscsi-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-logical-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-mpath-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-rbd-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-driver-storage-scsi-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-hooks-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-lxc-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-qemu-6.0.0-lp152.9.3 is installed
  • OR libvirt-daemon-xen-6.0.0-lp152.9.3 is installed
  • OR libvirt-devel-6.0.0-lp152.9.3 is installed
  • OR libvirt-devel-32bit-6.0.0-lp152.9.3 is installed
  • OR libvirt-doc-6.0.0-lp152.9.3 is installed
  • OR libvirt-libs-6.0.0-lp152.9.3 is installed
  • OR libvirt-lock-sanlock-6.0.0-lp152.9.3 is installed
  • OR libvirt-nss-6.0.0-lp152.9.3 is installed
  • OR wireshark-plugin-libvirt-6.0.0-lp152.9.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • cups-filters-1.20.3-1 is installed
  • OR cups-filters-devel-1.20.3-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND shim-15+git47-25.11 is installed
  • BACK