The 6.12.15 stable kernel update contains a number of important fixes across the tree. The 6.12.14 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-cca2fcc70c 2025-02-20 02:26:22.548391+00:00 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 41 Version : 6.12.15 Release : 200.fc41 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.12.15 stable kernel update contains a number of important fixes across the tree. The 6.12.14 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 18 2025 Augusto Caringi [6.12.15-0] - Linux v6.12.15 * Mon Feb 17 2025 Augusto Caringi [6.12.14-0] - redhat/configs: automotive: Set CONFIG_FSCACHE=y (Augusto Caringi) - CONFIG_CPUFREQ_DT_PLATDEV is bool now (Justin M. Forbes) - Add some bugs to BugsFixed for the 6.12.14 update (Justin M. Forbes) - efi,lockdown: fix kernel lockdown on Secure Boot (Ondrej Mosnacek) {CVE-2025-1272} - Linux v6.12.14 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2333706 - Kernel 6.12.6 kernel lockdown disabled https://bugzilla.redhat.com/show_bug.cgi?id=2333706 [ 2 ] Bug #2345700 - CVE-2025-1272 kernel: Secure Boot does not automatically enable kernel lockdown [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2345700 [ 3 ] Bug #2345701 - CVE-2025-1272 kernel: Secure Boot does not automatically enable kernel lockdown [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2345701 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-cca2fcc70c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 . # Security update for installation-images Announcement ID: SUSE-SU-2024:4347-1 Release Date: 2024-12-17T08:36:40Z Rating: important References: * bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that has one security fix can now be installed. ## Description: This update updates installation-images and tftpboot images to contain the latest shim for secure boot. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-4347=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-4347=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * tftpboot-installation-SLE-Micro-5.3-s390x-16.57.21-150400.3.4.2 * tftpboot-installation-SLE-Micro-5.3-x86_64-16.57.21-150400.3.4.2 * tftpboot-installation-SLE-Micro-5.3-aarch64-16.57.21-150400.3.4.2 * SUSE Linux Enterprise Micro 5.3 (noarch) * tftpboot-installation-SLE-Micro-5.3-s390x-16.57.21-150400.3.4.2 * tftpboot-installation-SLE-Micro-5.3-x86_64-16.57.21-150400.3.4.2 * tftpboot-installation-SLE-Micro-5.3-aarch64-16.57.21-150400.3.4.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1233813 . This security advisory details a critical patch for SUSE Linux Enterprise Micro installation images to protect against vulnerabilities and enhance system integrity. SUSE Linux, installation images, secure boot, micro services, patch updates. . Severity: Important. LinuxSecurity.com Team
* bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 . # Security update for installation-images Announcement ID: SUSE-SU-2024:4350-1 Release Date: 2024-12-17T09:05:12Z Rating: important References: * bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that has one security fix can now be installed. ## Description: This update updates installation-images and tftpboot images to contain the latest shim for secure boot. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-4350=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-4350=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * tftpboot-installation-SLE-Micro-5.4-aarch64-16.57.26-150400.3.4.1 * tftpboot-installation-SLE-Micro-5.4-x86_64-16.57.26-150400.3.4.1 * tftpboot-installation-SLE-Micro-5.4-s390x-16.57.26-150400.3.4.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * tftpboot-installation-SLE-Micro-5.4-aarch64-16.57.26-150400.3.4.1 * tftpboot-installation-SLE-Micro-5.4-x86_64-16.57.26-150400.3.4.1 * tftpboot-installation-SLE-Micro-5.4-s390x-16.57.26-150400.3.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1233813 . Critical patch for installation-images within SUSE Linux Enterprise. Essential upgrades provided to meet secure boot standards.. SUSE Linux Enterprise, installation-images security, security patches, secure boot updates. . Severity: Important. LinuxSecurity.com Team
* bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 . # Security update for installation-images Announcement ID: SUSE-SU-2024:4351-1 Release Date: 2024-12-17T09:33:35Z Rating: important References: * bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that has one security fix can now be installed. ## Description: This update updates installation-images and tftpboot images to contain the latest shim for secure boot. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-4351=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-4351=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (noarch) * tftpboot-installation-SLE-Micro-5.2-x86_64-16.56.14-150300.3.4.1 * tftpboot-installation-SLE-Micro-5.2-s390x-16.56.14-150300.3.4.1 * tftpboot-installation-SLE-Micro-5.2-aarch64-16.56.14-150300.3.4.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (noarch) * tftpboot-installation-SLE-Micro-5.2-x86_64-16.56.14-150300.3.4.1 * tftpboot-installation-SLE-Micro-5.2-s390x-16.56.14-150300.3.4.1 * tftpboot-installation-SLE-Micro-5.2-aarch64-16.56.14-150300.3.4.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1233813 . Enhancements to installation media bolster secure boot reliability in SUSE Linux Enterprise Micro 5.2 along with Rancher setups.. SUSE Linux Enterprise, installation updates, secure boot, patch management, security announcements. . Severity: Important. LinuxSecurity.com Team
Mate Kukri discovered the Debian build of EDK2, a UEFI firmware implementation, used an insecure default configuration which could result in Secure Boot bypass via the UEFI shell. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3852-1
This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3813-1
Update to shim-15.8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2aa28a4cfc 2024-03-18 02:16:41.812974 -------------------------------------------------------------------------------- Name : shim Product : Fedora 38 Version : 15.8 Release : 2 URL : https://github.com/rhboot/shim/ Summary : First-stage UEFI bootloader Description : Initial UEFI bootloader that handles chaining to a trusted full bootloader under secure boot environments. This package contains the version signed by the UEFI signing service. -------------------------------------------------------------------------------- Update Information: Update to shim-15.8 -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 12 2024 Peter Jones - 15.8-2 - Update to shim-15.8 Resolves: CVE-2023-40546 Resolves: CVE-2023-40547 Resolves: CVE-2023-40548 Resolves: CVE-2023-40549 Resolves: CVE-2023-40550 Resolves: CVE-2023-40551 Resolves: rhbz#2113005 Resolves: rhbz#2189197 Resolves: rhbz#2238884 Resolves: rhbz#2259264 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2113005 - Live image made with BOOTX64.EFI from latest shim-x64-15.6-2 fails to boot on some boards https://bugzilla.redhat.com/show_bug.cgi?id=2113005 [ 2 ] Bug #2198977 - Secure boot shim cert seems to be out of date (exp. Dec. 2022) https://bugzilla.redhat.com/show_bug.cgi?id=2198977 [ 3 ] Bug #2238884 - Version bump to 15.7 https://bugzilla.redhat.com/show_bug.cgi?id=2238884 [ 4 ] Bug #2259264 - Fedora fails to boot via BOOT/bootaa64-> fbaa64 on UEFI machines with EFI_MEMORY_ATTRIBUTES_PROTOCOL https://bugzilla.redhat.com/show_bug.cgi?id=2259264 -------------------------------------------------------------------------------- This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2024-2aa28a4cfc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update of installation-images fixes the following issues: rebuild the package with the new secure boot key (bsc#1209188).. # Security update for installation-images Announcement ID: SUSE-SU-2023:2826-1 Rating: moderate References: * bsc#1209188 Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Manager Proxy 4.2 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Server 4.2 An update that has one security fix can now be installed. ## Description: This update of installation-images fixes the following issues: * rebuild the package with the new secure boot key (bsc#1209188). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-2826=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-2826=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-2826=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-2826=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2023-2826=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-2826=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-2826=1 * SUSE LinuxEnterprise Real Time 15 SP3 zypper in -t patch SUSE-SLE-Product-RT-15-SP3-2023-2826=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-2826=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-2826=1 ## Package List: * SUSE Manager Proxy 4.2 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * SUSE Manager Retail Branch Server 4.2 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * SUSE Manager Server 4.2 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * SUSE Enterprise Storage 7.1 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64) * installation-images-debuginfodeps-SLES-16.56.15-150300.3.17.19 * install-initrd-SLES-16.56.15-150300.3.17.19 * installation-images-SLES-16.56.15-150300.3.17.19 * skelcd-installer-SLES-16.56.15-150300.3.17.19 * skelcd-installer-net-SLES-16.56.15-150300.3.17.19 * openSUSE Leap 15.3 (noarch) *tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * SUSE Linux Enterprise Real Time 15 SP3 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * tftpboot-installation-SLE-15-SP3-aarch64-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-ppc64le-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-s390x-16.56.15-150300.3.17.19 * tftpboot-installation-SLE-15-SP3-x86_64-16.56.15-150300.3.17.19 ## References: *https://bugzilla.suse.com/show_bug.cgi?id=1209188 . The recent security advisory released for openSUSE includes important updates to installation images, focusing on severe vulnerabilities associated with secure boot keys.. openSUSE Installation Update, Security Patch, Installation Images, Secure Boot Key. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.