- Issued:
- 2023-04-25
- Updated:
- 2023-04-25
RHBA-2023:1991 - Bug Fix Advisory
Synopsis
shim bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for shim is now available for Red Hat Enterprise Linux 7.
Description
The shim package contains a first stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.
Bug Fix(es) and Enhancement(s):
- Shim refuses to boot the system when TPM event logging fails. (BZ#2002648)
- Shim loops indefinitely processing certificates when space in mok is smaller than certificate size. (BZ#2007084)
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Enterprise Linux Server 7 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
- Red Hat Enterprise Linux Workstation 7 x86_64
- Red Hat Enterprise Linux Desktop 7 x86_64
- Red Hat Enterprise Linux for Scientific Computing 7 x86_64
Fixes
- BZ - 2002648 - Shim refuses to boot the system when TPM event logging fails [rhel-7.9.z]
- BZ - 2007084 - shim loops indefinitely processing certificates when space in mok is smaller than certificate size
CVEs
(none)
References
(none)
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux Server 7
SRPM | |
---|---|
shim-15.6-3.el7.src.rpm | SHA-256: 63c900003819c46817d6c350853ef7e9664969286ce8e1252873adc6afa8cf42 |
shim-signed-15.6-3.el7_9.src.rpm | SHA-256: 5d79a414b5cd207bd9c6f7e73e36ab8670541e1b1d713abb4ed6b8a4101feb3b |
x86_64 | |
mokutil-15.6-3.el7_9.x86_64.rpm | SHA-256: a287f102345c55ed2520645ccc59d9a623b55d63344282838e02ced64f52ea40 |
mokutil-debuginfo-15.6-3.el7_9.x86_64.rpm | SHA-256: bebf85a5bc867b41e1722123d7eb05e3c88ef1aabd2ffb932bf1dd9e187a25ae |
shim-ia32-15.6-3.el7_9.x86_64.rpm | SHA-256: 8014425894c0809c7340890819fae50f4e5864e1822972969a0399c4a254ebd2 |
shim-unsigned-ia32-15.6-3.el7.x86_64.rpm | SHA-256: 5c7b2697ef1995917eb106a349ce40faeaae74461a7adf8d64bbe1eeed92a28a |
shim-unsigned-x64-15.6-3.el7.x86_64.rpm | SHA-256: 385dc978aa8b2bab6a415a10157907a9427a04d804aecb92ef7e19cf5e616e31 |
shim-x64-15.6-3.el7_9.x86_64.rpm | SHA-256: 7198d8686e6ebebbfb9c388c80899450239a9279d7a207972a6eb5133da23445 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 7
SRPM | |
---|---|
shim-15.6-3.el7.src.rpm | SHA-256: 63c900003819c46817d6c350853ef7e9664969286ce8e1252873adc6afa8cf42 |
shim-signed-15.6-3.el7_9.src.rpm | SHA-256: 5d79a414b5cd207bd9c6f7e73e36ab8670541e1b1d713abb4ed6b8a4101feb3b |
x86_64 | |
mokutil-15.6-3.el7_9.x86_64.rpm | SHA-256: a287f102345c55ed2520645ccc59d9a623b55d63344282838e02ced64f52ea40 |
mokutil-debuginfo-15.6-3.el7_9.x86_64.rpm | SHA-256: bebf85a5bc867b41e1722123d7eb05e3c88ef1aabd2ffb932bf1dd9e187a25ae |
shim-ia32-15.6-3.el7_9.x86_64.rpm | SHA-256: 8014425894c0809c7340890819fae50f4e5864e1822972969a0399c4a254ebd2 |
shim-unsigned-ia32-15.6-3.el7.x86_64.rpm | SHA-256: 5c7b2697ef1995917eb106a349ce40faeaae74461a7adf8d64bbe1eeed92a28a |
shim-unsigned-x64-15.6-3.el7.x86_64.rpm | SHA-256: 385dc978aa8b2bab6a415a10157907a9427a04d804aecb92ef7e19cf5e616e31 |
shim-x64-15.6-3.el7_9.x86_64.rpm | SHA-256: 7198d8686e6ebebbfb9c388c80899450239a9279d7a207972a6eb5133da23445 |
Red Hat Enterprise Linux Workstation 7
SRPM | |
---|---|
shim-15.6-3.el7.src.rpm | SHA-256: 63c900003819c46817d6c350853ef7e9664969286ce8e1252873adc6afa8cf42 |
shim-signed-15.6-3.el7_9.src.rpm | SHA-256: 5d79a414b5cd207bd9c6f7e73e36ab8670541e1b1d713abb4ed6b8a4101feb3b |
x86_64 | |
mokutil-15.6-3.el7_9.x86_64.rpm | SHA-256: a287f102345c55ed2520645ccc59d9a623b55d63344282838e02ced64f52ea40 |
mokutil-debuginfo-15.6-3.el7_9.x86_64.rpm | SHA-256: bebf85a5bc867b41e1722123d7eb05e3c88ef1aabd2ffb932bf1dd9e187a25ae |
shim-ia32-15.6-3.el7_9.x86_64.rpm | SHA-256: 8014425894c0809c7340890819fae50f4e5864e1822972969a0399c4a254ebd2 |
shim-unsigned-ia32-15.6-3.el7.x86_64.rpm | SHA-256: 5c7b2697ef1995917eb106a349ce40faeaae74461a7adf8d64bbe1eeed92a28a |
shim-unsigned-x64-15.6-3.el7.x86_64.rpm | SHA-256: 385dc978aa8b2bab6a415a10157907a9427a04d804aecb92ef7e19cf5e616e31 |
shim-x64-15.6-3.el7_9.x86_64.rpm | SHA-256: 7198d8686e6ebebbfb9c388c80899450239a9279d7a207972a6eb5133da23445 |
Red Hat Enterprise Linux Desktop 7
SRPM | |
---|---|
shim-15.6-3.el7.src.rpm | SHA-256: 63c900003819c46817d6c350853ef7e9664969286ce8e1252873adc6afa8cf42 |
shim-signed-15.6-3.el7_9.src.rpm | SHA-256: 5d79a414b5cd207bd9c6f7e73e36ab8670541e1b1d713abb4ed6b8a4101feb3b |
x86_64 | |
mokutil-15.6-3.el7_9.x86_64.rpm | SHA-256: a287f102345c55ed2520645ccc59d9a623b55d63344282838e02ced64f52ea40 |
mokutil-debuginfo-15.6-3.el7_9.x86_64.rpm | SHA-256: bebf85a5bc867b41e1722123d7eb05e3c88ef1aabd2ffb932bf1dd9e187a25ae |
shim-ia32-15.6-3.el7_9.x86_64.rpm | SHA-256: 8014425894c0809c7340890819fae50f4e5864e1822972969a0399c4a254ebd2 |
shim-unsigned-ia32-15.6-3.el7.x86_64.rpm | SHA-256: 5c7b2697ef1995917eb106a349ce40faeaae74461a7adf8d64bbe1eeed92a28a |
shim-unsigned-x64-15.6-3.el7.x86_64.rpm | SHA-256: 385dc978aa8b2bab6a415a10157907a9427a04d804aecb92ef7e19cf5e616e31 |
shim-x64-15.6-3.el7_9.x86_64.rpm | SHA-256: 7198d8686e6ebebbfb9c388c80899450239a9279d7a207972a6eb5133da23445 |
Red Hat Enterprise Linux for Scientific Computing 7
SRPM | |
---|---|
shim-15.6-3.el7.src.rpm | SHA-256: 63c900003819c46817d6c350853ef7e9664969286ce8e1252873adc6afa8cf42 |
shim-signed-15.6-3.el7_9.src.rpm | SHA-256: 5d79a414b5cd207bd9c6f7e73e36ab8670541e1b1d713abb4ed6b8a4101feb3b |
x86_64 | |
mokutil-15.6-3.el7_9.x86_64.rpm | SHA-256: a287f102345c55ed2520645ccc59d9a623b55d63344282838e02ced64f52ea40 |
mokutil-debuginfo-15.6-3.el7_9.x86_64.rpm | SHA-256: bebf85a5bc867b41e1722123d7eb05e3c88ef1aabd2ffb932bf1dd9e187a25ae |
shim-ia32-15.6-3.el7_9.x86_64.rpm | SHA-256: 8014425894c0809c7340890819fae50f4e5864e1822972969a0399c4a254ebd2 |
shim-unsigned-ia32-15.6-3.el7.x86_64.rpm | SHA-256: 5c7b2697ef1995917eb106a349ce40faeaae74461a7adf8d64bbe1eeed92a28a |
shim-unsigned-x64-15.6-3.el7.x86_64.rpm | SHA-256: 385dc978aa8b2bab6a415a10157907a9427a04d804aecb92ef7e19cf5e616e31 |
shim-x64-15.6-3.el7_9.x86_64.rpm | SHA-256: 7198d8686e6ebebbfb9c388c80899450239a9279d7a207972a6eb5133da23445 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.