SUSE-RU-2026:23410-1: moderate: Recommended update for fwupd

SLE-UPDATES null at suse.de
Wed Sep 2 12:32:10 UTC 2026


# Recommended update for fwupd

Announcement ID: SUSE-RU-2026:23410-1  
Release Date: 2026-08-31T09:23:06Z  
Rating: moderate  
References:

  * bsc#1217138

  
Affected Products:

  * SUSE Linux Micro 6.2

  
  
An update that has one fix can now be installed.

## Description:

This update for fwupd fixes the following issues:

Changes in fwupd:

  * Update to version 2.1.6:
  * This release adds the following features:
    * Add --filter-protocol to fwupdmgr and fwupdtool
    * Add a new HSI attribute for coreboot verified boot
    * Add hashes for the latest DBX for offline machines
    * Allow parsing Hayden Bridge Thunderbolt firmware
    * Handle HPE Redfish reset-required updates
    * Ignore efivar free space on VMWare, GCE and EC2 VMs
    * Prevent FwupdClient from downloading the same file multiple times
    * Split UEFI Memory Protection HSI from NX Compat
  * This release fixes the following bugs:
    * Avoid an integer overflow in the ifwi-cpd manifest length check
    * Avoid truncating the AMD Kria FRU board area offset
    * Block dbx updates on ASUSTeK GL553VD
    * Check SMEE hardware bit directly for AMD SME detection
    * Create the ESP OS directory if not found
    * Detect the BCR device on Celeron LPC SPI controllers
    * Fall back to a binary firmware when no specific MTD image type is set
    * Fix AI table clear behavior of the elantp boot code.
    * Fix errors with fwupd-refresh service not working properly
    * Fix Genesys GL32xx device locker crash due to argument mismatch
    * Fix installing KEK updates when using snapd by sending the correct blob
    * Fix integer underflow when Elan firmware is smaller than one page
    * Fix possible NULL pointer dereference when updating SteelSeries firmware
    * Fix the display of the HP UEFI db certificate
    * Improved usi-dock progress reporting behavior
    * Increase the parser item limit from 100 to 1000 for large KEKs
    * Log out of the Redfish session when required on HPE hardware
    * Only show 'authenticating' after a short delay
    * Re-process the device metadata when required after all devices are added
    * Require sealed memfd input to prevent possible TOCTOU attacks
    * Sanitise the Jabra GNP device version in a more secure way
    * Validate raydium-tp buffer size before direct index access
    * Validate that Lenovo dock device-reported program sizes are valid
  * This release adds support for the following hardware:

    * Lenovo dual-bank accessory dongle and paired peripherals
  * Migrate to manual service run

  * Set the fallback shim path for SUSE/openSUSE (bsc#1217138)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Micro 6.2  
    zypper in -t patch SUSE-SL-Micro-6.2-1567=1

## Package List:

  * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64)
    * libfwupd3-debuginfo-2.1.6-160000.1.1
    * fwupd-debugsource-2.1.6-160000.1.1
    * fwupd-debuginfo-2.1.6-160000.1.1
    * fwupd-2.1.6-160000.1.1
    * libfwupd3-2.1.6-160000.1.1
    * typelib-1_0-Fwupd-2_0-2.1.6-160000.1.1

## References:

  * https://bugzilla.suse.com/show_bug.cgi?id=1217138

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20260902/97994ab2/attachment-0001.htm>


More information about the sle-updates mailing list