Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-78691

rhel 9.3 contains newer version of shim than rhel 9.4+

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhel-9.4.z, rhel-9.5.z
    • shim
    • None
    • Yes
    • None
    • rhel-bootloader
    • ssg_core_services
    • 3
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None

      What were you trying to do that didn't work?

      There were 2 advisories released to customers for shim to rhel9

      The version in rhel 9.4 is lower than in 9.3. One would need to downgrade shim to get the version from 9.3

      Python 3.9.21 (main, Dec  5 2024, 00:00:00) 
      [GCC 11.5.0 20240719 (Red Hat 11.5.0-2)] on linux
      Type "help", "copyright", "credits" or "license" for more information.
      >>> import rpm
      >>> rpm.ver('shim-15.8-4.el9_3') <= rpm.ver('shim-15.8-3.el9_4')
      False
      

      What is the impact of this issue to you?

      RHEL cloud images for AWS and Azure are built from the RHEL 9.5(9.4 for EUS) compose.
      and thus they got installed lower version than in the rhel9.3 which is RHSA advisory)

      Please provide the package NVR for which the bug is seen:

      • shim-15.8-3.el9_4

      How reproducible is this bug?:

      Deterministic

      Expected results

      version of shim in rhel 9.5 is bigger than version in rhel 9.4 "shim-15.8-4.el9_3"

      Additional Info

      Similar issue as in RHEL-78688 and was reported by the AWS team.

              bootloader-eng-team bootloader -eng-team
              lslebodn@redhat.com Lukas Slebodnik
              bootloader -eng-team bootloader -eng-team
              Release Test Team Release Test Team
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: