SUSE-IU-2026:6547-1: Recommended update of suse/sl-micro/6.1/base-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Aug 28 07:29:44 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6547-1
Image Tags        : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.175 , suse/sl-micro/6.1/base-os-container:latest
Image Release     : 5.175
Severity          : moderate
Type              : recommended
References        : 1254336 1261833 1269084 1270036 CVE-2026-39881 
-----------------------------------------------------------------

The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 691
Released:    Thu Aug 27 15:53:07 2026
Summary:     Recommended update for shim
Type:        recommended
Severity:    moderate
References:  1254336,1261833,1269084,1270036,CVE-2026-39881
This update for shim fixes the following issues:

- shim-install: Do not update fallback on sl-micro when the fallback
  is not in efi default boot path

  The SL-Micro SelfInstall image direct unpackage the raw image to
  the hard drive on target machine. The kiwi produced the raw image
  by 'shim-install --removable' command. So the raw image does NOT
  include fallback.efi in the EFI default boot path (aka. the
  removable boot path, EFI/boot/). Looks that SL-Micro does NOT care
  the fallback function of SUSE boot entry is lost.

  Normally, with or without fallback.efi should NOT case problem when
  booting. Also, the distro (SL-Micro in this case) does NOT care fallback
  function. But some issue machine's firmware can ONLY boot with the
  removable boot path (aka. the default boot path, /EFI/boot/bootx64.efi).
  And issue firmware always modified boot order or even removed SUSE boot
  entry. It causes that the fallback.efi always be triggered in every
  booting. The outward symptom is an endless cycle of rebooting and showing
  the fallback prompt box.

  The above situation NOT be found before we fix bsc#1254336. In
  bsc#1254336, the shim-install did NOT update the files in removable boot
  path. e.g. /EFI/boot/bootx64.efi or /EFI/boot/fallback.efi.

  So we will NOT update fallback.efi on SL-Micro when shim-install did NOT
  see fallback in the removable boot path (EFI/boot/fallback.efi). No
  fallback.efi in the removable boot path means that the target system
  is installed by wiki raw image.  (bsc#1270036)

- shim-install: Improve the detection of SL Micro

  The GRUB_DISTRIBUTOR variable in SL Micro images may contain
  'SL Micro' or 'SL-Micro' prefix. (bsc#1269084)


The following package changes have been done:

- shim-16.1-slfo.1.1_2.1 updated
- SL-Micro-release-6.1-slfo.1.12.67 updated
- container:suse-toolbox-image-1.0.0-5.93 updated


More information about the sle-container-updates mailing list