Alerts This Week
Warning Icon 1 545
Alerts This Week
Warning Icon 1 545

SUSE Shim Moderate Security Update CVE-2024-2312 Advisory 2026-0741-2

suse
Calendar Grey June 16, 2026
Dist Suse Esm H88
A security update for SUSE addressing a moderate severity vulnerability in shim to enhance system security and stability.
An update that solves one vulnerability and has one security fix can now be installed.

Summary

## This update for shim fixes the following issues: shim is updated to version 16.1: * shim_start_image(): fix guid/handle pairing when uninstalling protocols * Fix uncompressed ipv6 netboot * fix test segfaults caused by uninitialized memory * SbatLevel_Variable.txt: minor typo fix. * Realloc() needs to allocate one more byte for sprintf() * IPv6: Add more check to avoid multiple double colon and illegal char * Loader proto v2 * loader-protocol: add workaround for EDK2 2025.02 page fault on FreePages * Generate Authenticode for the entire PE file * README: mention new loader protocol and interaction with UKIs * shim: change automatically enable MOK_POLICY_REQUIRE_NX * Save var info * add SbatLevel entry 2025051000 for PSA-2025-00012-1 * Coverity fixes 20250804 * fix http boot

References

* bsc#1240871

* bsc#1247432

Cross-

* CVE-2024-2312

CVSS scores:

* CVE-2024-2312 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

* CVE-2024-2312 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server 15 SP6 LTSS

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves one vulnerability and has one security fix can now be

installed.

##

* https://www.suse.com/security/cve/CVE-2024-2312.html

* https://bugzilla.suse.com/show_bug.cgi?id=1240871

* https://bugzilla.suse.com/show_bug.cgi?id=1247432

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0741-2
Release Date: 2026-06-16T14:41:50Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here