This update for shim fixes the following issues:
This update addresses the 'BootHole' security issue (master CVE CVE-2020-10713), by disallowing binaries signed by the previous SUSE UEFI signing key from booting.
This update should only be installed after updates of grub2, the Linux kernel and (if used) Xen from July / August 2020 are applied.
Changes:
Use vendor-dbx to block old SUSE/openSUSE signkeys (bsc#1168994)
Add vendor-dbx.bin as the vendor dbx to block unwanted keys
Update the path to grub-tpm.efi in shim-install (bsc#1174320)