SUSE-IU-2026:6547-1: Recommended update of suse/sl-micro/6.1/base-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Aug 28 07:29:44 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6547-1
Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.175 , suse/sl-micro/6.1/base-os-container:latest
Image Release : 5.175
Severity : moderate
Type : recommended
References : 1254336 1261833 1269084 1270036 CVE-2026-39881
-----------------------------------------------------------------
The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 691
Released: Thu Aug 27 15:53:07 2026
Summary: Recommended update for shim
Type: recommended
Severity: moderate
References: 1254336,1261833,1269084,1270036,CVE-2026-39881
This update for shim fixes the following issues:
- shim-install: Do not update fallback on sl-micro when the fallback
is not in efi default boot path
The SL-Micro SelfInstall image direct unpackage the raw image to
the hard drive on target machine. The kiwi produced the raw image
by 'shim-install --removable' command. So the raw image does NOT
include fallback.efi in the EFI default boot path (aka. the
removable boot path, EFI/boot/). Looks that SL-Micro does NOT care
the fallback function of SUSE boot entry is lost.
Normally, with or without fallback.efi should NOT case problem when
booting. Also, the distro (SL-Micro in this case) does NOT care fallback
function. But some issue machine's firmware can ONLY boot with the
removable boot path (aka. the default boot path, /EFI/boot/bootx64.efi).
And issue firmware always modified boot order or even removed SUSE boot
entry. It causes that the fallback.efi always be triggered in every
booting. The outward symptom is an endless cycle of rebooting and showing
the fallback prompt box.
The above situation NOT be found before we fix bsc#1254336. In
bsc#1254336, the shim-install did NOT update the files in removable boot
path. e.g. /EFI/boot/bootx64.efi or /EFI/boot/fallback.efi.
So we will NOT update fallback.efi on SL-Micro when shim-install did NOT
see fallback in the removable boot path (EFI/boot/fallback.efi). No
fallback.efi in the removable boot path means that the target system
is installed by wiki raw image. (bsc#1270036)
- shim-install: Improve the detection of SL Micro
The GRUB_DISTRIBUTOR variable in SL Micro images may contain
'SL Micro' or 'SL-Micro' prefix. (bsc#1269084)
The following package changes have been done:
- shim-16.1-slfo.1.1_2.1 updated
- SL-Micro-release-6.1-slfo.1.12.67 updated
- container:suse-toolbox-image-1.0.0-5.93 updated
More information about the sle-container-updates
mailing list