Debian Security Advisory

DLA-3312-1 shim -- LTS security update

Date Reported:
08 Feb 2023
Affected Packages:
shim
Vulnerable:
Yes
Security database references:
No other external database security references currently available.
More information:

This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable.

Additionally, this update blocks old, insecure versions of GRUB. Thus an update to a signed GRUB 2.06-3~deb10u3 package as released in DLA 3190-2 must be in place prior to updating the shim packages.

For Debian 10 buster, this problem has been fixed in version 15.7-1~deb10u1.

We recommend that you upgrade your shim packages.

For the detailed security status of shim please refer to its security tracker page at: https://security-tracker.debian.org/tracker/shim

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS