# BIOS Release Notes not sufficiently transparant / accurate?

**URL:** <https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823>\
**Category:** Framework Laptop 13\
**Tags:** intel-11th, bios\
**Created:** [October 16, 2025, 5:20am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823 "2025-10-16T05:20:48Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Second\_Coming](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/second_coming/32/29330_2.png) [@Second\_Coming](https://community.frame.work/u/Second_Coming)\
**Post date:** [October 16, 2025, 5:20am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/1 "2025-10-16T05:20:48Z")

</div>

Given this:

> **[BombShell: The Signed Backdoor Hiding in Plain Sight on Framework Devices](https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/)**
>
> Eclypsium researchers have discovered UEFI shells, authorized via Secure Boot, on Framework laptops. The UEFI shells contain capabilities that allow attackers to bypass Secure Boot on roughly 200,000 affected Framework laptops and desktops.

Shouldn’t there be mention of it in the BIOS release notes, such as this:

> [@Framework Laptop 13 - 11th Gen Intel Core BIOS 3.24 Release STABLE](https://community.frame.work/t/framework-laptop-13-11th-gen-intel-core-bios-3-24-release-stable/75534):
>
> Highlights Added Framework’s dbx key and updated the default CA of Windows Secure Boot. Introduced Battery Charge Limiting status functionality. Fixed an issue where hardware encryption on OPAL drives could cause a missing boot drive on subsequent reboots. Security Fixed - CVE-2024-45332, CVE-2025-4275 NOTE This BIOS update is a multi-part update, meaning you will need to update to 3.23, and then update to 3.24. This is due to an issue that cannot update the new Microsoft secure boot CA if you…

Or is it there, and I just don’t know what I’m reading to link the two things together?

---

<div class="post-metadata">

**Author:** ![truffaldino](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/truffaldino/32/13219_2.png) [@truffaldino](https://community.frame.work/u/truffaldino)\
**Post date:** [October 16, 2025, 7:44am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/2 "2025-10-16T07:44:17Z")

</div>

Thanks for the heads-up. A fascinating and well-presented read.

I’m sorry I can’t offer an answer to your final question (but I’m keen to learn what the answer is).

---

<div class="post-metadata">

**Author:** ![fritzmg](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/fritzmg/32/2429_2.png) [@fritzmg](https://community.frame.work/u/fritzmg)\
**Post date:** [October 16, 2025, 1:57pm UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/3 "2025-10-16T13:57:54Z")

</div>

The security fixes are listed under **Security Fixes** on the respective download pages.

---

<div class="post-metadata">

**Author:** ![Tommi\_Virtanen](https://avatars.discourse-cdn.com/v4/letter/t/cc9497/32.png) [@Tommi\_Virtanen](https://community.frame.work/u/Tommi_Virtanen)\
**Post date:** [October 16, 2025, 3:14pm UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/4 "2025-10-16T15:14:45Z")

</div>

Researchers that don’t quote CVE numbers are frustrating to follow. It seems the “BombShell” thing by Eclypsium is the same as [UEFI Secure Boot bypass](https://www.binarly.io/advisories/brly-dva-2025-001) which is [NVD - CVE-2025-3052](https://nvd.nist.gov/vuln/detail/CVE-2025-3052) and that is _not_ mentioned in the BIOS release notes.

---

<div class="post-metadata">

**Author:** ![Second\_Coming](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/second_coming/32/29330_2.png) [@Second\_Coming](https://community.frame.work/u/Second_Coming)\
**Post date:** [October 16, 2025, 5:11pm UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/5 "2025-10-16T17:11:31Z")

</div>

Exactly…and I don’t see this mentioned in the Security Fixes section explicitly.

…unless the ‘boomshell’ is the CVE-2025-4275.

…which goes to Tommi’s point on missing CVE from the researcher’s article, and / or CVE-2025-3052 is not mentioned in the BIOS release note.

Again, it could be me not seeing / realising / linking two things together.

“CVE-2025-3052” only has two mentions in the forum (base on forum search).

---

<div class="post-metadata">

**Author:** ![fritzmg](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/fritzmg/32/2429_2.png) [@fritzmg](https://community.frame.work/u/fritzmg)\
**Post date:** [October 16, 2025, 8:03pm UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/6 "2025-10-16T20:03:24Z")

</div>

It is CVE-2025-3052 as far as I understand it, yes.

---

<div class="post-metadata">

**Author:** ![Second\_Coming](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/second_coming/32/29330_2.png) [@Second\_Coming](https://community.frame.work/u/Second_Coming)\
**Post date:** [October 16, 2025, 8:33pm UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/7 "2025-10-16T20:33:48Z")

</div>

…and so CVE-2025-3052 has not been addressed in any recent BIOS updates?

---

<div class="post-metadata">

**Author:** ![DHowett](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/dhowett/32/1990_2.png) [@DHowett](https://community.frame.work/u/DHowett)\
**Post date:** [October 17, 2025, 2:54am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/8 "2025-10-17T02:54:33Z")

</div>

This is not CVE-2025-3052. If you follow the link from the [the NVD vulnerability page](https://nvd.nist.gov/vuln/detail/CVE-2025-3052) linked by @tommi_virtanen above to the [vulnerability report at cert.org](https://www.kb.cert.org/vuls/id/806555), it says the following:

> UEFI firmware applications `DTBios` and `BiosFlashShell` from [DTResearch](https://dtresearch.com) contain a vulnerability that allows Secure Boot to be bypassed using a specially crafted NVRAM variable.  
> _[cert.org](https://www.kb.cert.org/vuls/id/806555)_

Neither `DTBios` nor `BiosFlashShell` are the UEFI shell implicated in Eclipsium’s article.

It goes on to say,

> The vulnerability stems from improper handling of a runtime NVRAM variable that enables an arbitrary write primitive  
> _ibid._

The `mm` command documented in Eclipsium’s report is not “improper handling of a runtime NVRAM variable.”

It is possible a CVE has not yet been issued for this vulnerability. Perhaps no CNA has been involved.

The release notes you are assessing as being insufficiently transparent or accurate state:

> Added Framework’s dbx key  
> _[3.24 release thread](https://community.frame.work/t/framework-laptop-13-11th-gen-intel-core-bios-3-24-release-stable/75534)_

This tracks with Eclipsium’s table indicating that _a DBX update was targeted for release in 1.24_.

 ![image](https://us1.discourse-cdn.com/flex001/uploads/framework3/original/3X/8/0/80fc8980596a0dbf2a61395248db8b42358374b5.png)

QED

---

<div class="post-metadata">

**Author:** ![Second\_Coming](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/second_coming/32/29330_2.png) [@Second\_Coming](https://community.frame.work/u/Second_Coming)\
**Post date:** [October 17, 2025, 3:12am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/9 "2025-10-17T03:12:37Z")

</div>

> [@DHowett](#):
>
> This tracks with Eclipsium’s table indicating that _a DBX update was targeted for release_

Great, I was gathering as much when I was searching for “DBX” in the release note…which brought me to the “not sufficiently” section of the thread’s title. (see below)

Given this:

 ![image](https://us1.discourse-cdn.com/flex001/uploads/framework3/original/3X/6/a/6a842cba3111bd233590fed00fec22bbb293f6b7.png)

There’s only mention of “ **Added** Framework’s dbx key”, and no mention of wording to the effect of “blacklist” or revocation of key(s)? Also, no details on the effect / intent of the “added” DBX key, and also no mention of a vulnerability / security posture improvement of the added DBX key. Plus, if it’s to address a security concern (with or without CVE assigned), then the release note should have mention of this specifically under the “Security Fixes” section.

(I intentionally left the first post ‘open’…in order to arrive to this point of the discussion because I wasn’t sure if that addition of DBX key is related to this issue. Thanks for the confirmation)

---

<div class="post-metadata">

**Author:** ![pkunk](https://avatars.discourse-cdn.com/v4/letter/p/df705f/32.png) [@pkunk](https://community.frame.work/u/pkunk)\
**Post date:** [October 17, 2025, 5:26am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/10 "2025-10-17T05:26:02Z")

</div>

I was getting the feeling from the few articles I read today that this is certainly not Framework specific and relates to other vendor machines. Though the inclusion of Framework and riding the whole XX # of Linux laptops did give the story the extra traction some of the news outlets were hoping for.

Clearly the function being referred to is commonly reserved for engineering and platforms that are much more open (like Framework) than the majority of walled off systems, that guard any of these tools, is going to be the brunt of this “vulnerability”.

Just looking at the table quoted says that it is being addressed which may be more difficult to pin down with other manufacturers. It does go to show that while secure boot has made some improvements in security, there are still aspects of it that are not as mature as people are led to believe.

---

<div class="post-metadata">

**Author:** ![fritzmg](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/fritzmg/32/2429_2.png) [@fritzmg](https://community.frame.work/u/fritzmg)\
**Post date:** [October 17, 2025, 9:44am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/11 "2025-10-17T09:44:12Z")

</div>

> [@Second\_Coming](#):
>
> …and so CVE-2025-3052 has not been addressed in any recent BIOS updates?

It has (see the **Security notes** on the respective download page).

But alas I seem to have been wrong anyway (see @DHowett answer).

---

<div class="post-metadata">

**Author:** ![Second\_Coming](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/second_coming/32/29330_2.png) [@Second\_Coming](https://community.frame.work/u/Second_Coming)\
**Post date:** [October 17, 2025, 2:36pm UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/12 "2025-10-17T14:36:37Z")

</div>

> [@fritzmg](#):
>
> respective download page

You have a link to it?

(i.e. I don’t see mention of CVE-2025-3052 anywhere… I’m not looking in the right places?)

**Summary (So far)**:

1. You’re saying that CVE-2025-3052 has been addressed. –\> I’m not seeing that stated in Release Notes.
2. DHowett is saying the ‘fix’ for the ‘boomshell’ is the “Added Framework’s dbx key” –\> I’m saying those 4 words are not sufficiently transparent / accurate, and why doesn’t it comes under “Security Fixes”?

---

<div class="post-metadata">

**Author:** ![fritzmg](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/fritzmg/32/2429_2.png) [@fritzmg](https://community.frame.work/u/fritzmg)\
**Post date:** [October 17, 2025, 2:53pm UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/13 "2025-10-17T14:53:20Z")

</div>

> [@Second\_Coming](#):
>
> You have a link to it?
> 
> (i.e. I don’t see mention of CVE-2025-3052 anywhere… I’m not looking in the right places?)

Sorry, I was talking about `CVE-2025-4275`.

---

<div class="post-metadata">

**Author:** ![Second\_Coming](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/second_coming/32/29330_2.png) [@Second\_Coming](https://community.frame.work/u/Second_Coming)\
**Post date:** [October 18, 2025, 7:00pm UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/14 "2025-10-18T19:00:47Z")

</div>

…and that`CVE-2025-4275`seems to be different from the ‘bombshell’ matter, right?

---

<div class="post-metadata">

**Author:** ![Quin\_Chou](https://avatars.discourse-cdn.com/v4/letter/q/cdc98d/32.png) [@Quin\_Chou](https://community.frame.work/u/Quin_Chou)\
**Post date:** [December 3, 2025, 5:46am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/15 "2025-12-03T05:46:24Z")

</div>

We have already released BIOS updates for all affected products to implement the fix. The table below shows the specific BIOS version where the Framework dbx key was introduced. Please ensure your system is updated to the latest version.

| Products | Initial BIOS Version that contains limited shell | BIOS version that contains Framework dbx key |
| --- | --- | --- |
| Framework13 11th Gen Intel® Core™ | 3.24 | 3.24 |
| Framework13 12th Gen Intel® Core™ | 3.18 | 3.19 |
| Framework13 13th Gen Intel® Core™ | 3.08 | 3.09 |
| Framework13 Intel® Core™ Ultra Series 1 | 3.06 | 3.06 |
| Framework13 AMD Ryzen™ 7040 Series | 3.16 | 3.16 |
| Framework13 AMD Ryzen™ AI 300 Series | 3.04 | 3.05 |
| Framework16 AMD Ryzen™ 7040 Series (Laptop 16) | 3.07 | 3.07 |
| Framework Desktop AMD Ryzen™ AI 300 MAX Series | 3.01 | 3.03 |
| Framework 12 13th Gen Intel® Core™ | 3.06 | 3.06 |

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex001/uploads/framework3/original/1X/64c81a89f963ddb07633887baceb642a4b056046.png) [@system](https://community.frame.work/u/system)\
**Post date:** [June 1, 2026, 5:47am UTC](https://community.frame.work/t/bios-release-notes-not-sufficiently-transparant-accurate/76823/16 "2026-06-01T05:47:20Z")

</div>

This topic was automatically closed 180 days after the last reply. New replies are no longer allowed.
