SUSE-RU-2026:23352-1: moderate: Recommended update for shim

SLE-UPDATES null at suse.de
Mon Aug 31 16:38:52 UTC 2026


# Recommended update for shim

Announcement ID: SUSE-RU-2026:23352-1  
Release Date: 2026-08-27T13:53:07Z  
Rating: moderate  
References:

  * bsc#1254336
  * bsc#1269084
  * bsc#1270036

  
Affected Products:

  * SUSE Linux Micro 6.1

  
  
An update that has three fixes can now be installed.

## Description:

This update for shim fixes the following issues:

  * shim-install: Do not update fallback on sl-micro when the fallback is not in
    efi default boot path

The SL-Micro SelfInstall image direct unpackage the raw image to the hard drive
on target machine. The kiwi produced the raw image by 'shim-install --removable'
command. So the raw image does NOT include fallback.efi in the EFI default boot
path (aka. the removable boot path, EFI/boot/). Looks that SL-Micro does NOT
care the fallback function of SUSE boot entry is lost.

Normally, with or without fallback.efi should NOT case problem when booting.
Also, the distro (SL-Micro in this case) does NOT care fallback function. But
some issue machine's firmware can ONLY boot with the removable boot path (aka.
the default boot path, /EFI/boot/bootx64.efi). And issue firmware always
modified boot order or even removed SUSE boot entry. It causes that the
fallback.efi always be triggered in every booting. The outward symptom is an
endless cycle of rebooting and showing the fallback prompt box.

The above situation NOT be found before we fix bsc#1254336. In bsc#1254336, the
shim-install did NOT update the files in removable boot path. e.g.
/EFI/boot/bootx64.efi or /EFI/boot/fallback.efi.

So we will NOT update fallback.efi on SL-Micro when shim-install did NOT see
fallback in the removable boot path (EFI/boot/fallback.efi). No fallback.efi in
the removable boot path means that the target system is installed by wiki raw
image. (bsc#1270036)

  * shim-install: Improve the detection of SL Micro

The GRUB_DISTRIBUTOR variable in SL Micro images may contain "SL Micro" or "SL-
Micro" prefix. (bsc#1269084)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Micro 6.1  
    zypper in -t patch SUSE-SLE-Micro-6.1-691=1

## Package List:

  * SUSE Linux Micro 6.1 (aarch64 x86_64)
    * shim-debuginfo-16.1-slfo.1.1_2.1
    * shim-16.1-slfo.1.1_2.1
    * shim-debugsource-16.1-slfo.1.1_2.1

## References:

  * https://bugzilla.suse.com/show_bug.cgi?id=1254336
  * https://bugzilla.suse.com/show_bug.cgi?id=1269084
  * https://bugzilla.suse.com/show_bug.cgi?id=1270036

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260831/8a239d38/attachment-0001.htm>


More information about the sle-updates mailing list