Can't update the 3rd Party UEFI Signature Database due to lack of space in efivarfs

Which Linux distro are you using? Fedora

Which release version? 42

(If rolling release, last date updated?)

Which kernel are you using? 6.15.9-201.fc42.x86_64

Which BIOS version are you using? 03.09

Which Framework Laptop 13 model are you using? AMD Ryzen™ 7040 Series


I tried to run fwupdmgr get-updates and updating the 3rd Party UEFI Signature Database reports an update error:

Devices with no available firmware updates:
 • Windows Production PCA
 • frame.work-LaptopAMDDB
 • Hub
 • KEK CA
 • SBAT
 • ThinkPad Universal ThunderBolt 4 Dock
 • USB3.0 Hub
 • VMM6212
 • WD BLACK SN850X 1000GB
 • frame.work-LaptopAMDKEK
Devices with the latest available firmware version:
 • UEFI dbx
 • Fingerprint Sensor
 • System Firmware
 • ThinkPad Thunderbolt 4 Dock
Framework Laptop 13 (AMD Ryzen 7040Series)
│
└─UEFI CA:
  │   Device ID:          5bc922b7bd1adb5b6f99592611404036bd9f42d0
  │   Current version:    2011
  │   Vendor:             Microsoft (UEFI:Microsoft)
  │   Update Error:       Not enough efivarfs space, requested 16.4 kB and got 15.9 kB
  │   GUIDs:              26f42cba-9bf6-5365-802b-e250eb757e96 ← UEFI\VENDOR_Microsoft&NAME_Microsoft-UEFI-CA
  │                       c34a7e6a-bd86-5244-8bd0-7db66fd3c073 ← UEFI\CRT_E30CF09DABEAB32A6E3B07A7135245DE05FFB658
  │   Device Flags:       • Internal device
  │                       • Supported on remote server
  │                       • Needs a reboot after installation
  │                       • Updatable
  │                       • Signed Payload
  │                       • Can tag for emulation
  │
  └─Secure Boot Signature Database Configuration Update:
        New version:      2023
        Remote ID:        lvfs
        Release ID:       116503
        Summary:          UEFI Secure Boot Signature Database
        License:          Proprietary
        Size:             10.0 kB
        Created:          2025-04-29
        Urgency:          High
          Tested:         2025-07-24
          Distribution:   nixos 25.11
          Old version:    2011
          Version[fwupd]: 2.0.12
        Vendor:           Linux Foundation
        Release Flags:    • Trusted metadata
                          • Is upgrade
        Description:
        This updates the 3rd Party UEFI Signature Database (the "db") to the latest release from Microsoft. It also adds the latest OptionROM UEFI Signature Database update.
        Checksum:         6819c8098f09f4332a102194df6a033563aa288073b16315c5b88860fefb7e74

Not enough efivarfs space is the error in case it is hard to miss. Here is a list of EFI variables:

INFO: reading linux varstore from /sys/firmware/efi/efivars
AMD_PBS_SETUP       : blob: 1280 bytes
AMD_RAID            : qword: 0x0000000000000000
AcpiGlobalVariable  : qword: 0x000000005aeae000
AmdSetupPHX         : blob: 1663 bytes
AodSetupPhx         : blob: 806 bytes
ApSyncFlagNv        : dword: 0x52ea3f98
Boot0000            : boot entry: title="Fedora" devpath=Partition(nr=1)/FilePath(\EFI\fedora\shimx64.efi)
Boot0001            : boot entry: title="Fedora" devpath=Partition(nr=1)/FilePath(\EFI\fedora\shim.efi) optdata=5243
Boot0003            : boot entry: title="Windows Boot Manager" devpath=Partition(nr=2)/FilePath(\EFI\Microsoft\Boot\bootmgfw.efi) optdata=57494e444f5753000100000088000000780000004200430044004f0042004a004500430054003d007b00390064006500610038003600320063002d0035006300640064002d0034006500370030002d0061006300630031002d006600330032006200330034003400640034003700390035007d00000048000100000010000000040000007fff0400
Boot0004            : boot entry: title="Windows Boot Manager" devpath=Partition(nr=2)/FilePath(\EFI\Microsoft\Boot\bootmgfw.efi) optdata=57494e444f5753000100000088000000780000004200430044004f0042004a004500430054003d007b00390064006500610038003600320063002d0035006300640064002d0034006500370030002d0061006300630031002d006600330032006200330034003400640034003700390035007d00000048000100000010000000040000007fff0400
Boot2001            : blob: 42 bytes
Boot2002            : blob: 40 bytes
Boot2003            : blob: 36 bytes
BootOrder           : boot order: 0000, 0001, 2001, 2002, 2003
COMPAL              : blob: 32 bytes
Capsule0000         : blob: 48 bytes
CapsuleLast         : blob: 22 bytes
ConIn               : devpath: PciRoot()/PCI(dev=14:3)/ACPI(hid=0x30341d0,uid=0x0)
ConOut              : devpath: PciRoot()/PCI(dev=08:1)/PCI(dev=00:0)/GOP(adr=0x80010400)
CurrentPolicy       : byte: 0x02
CustomPlatformLang  : blob: 6 bytes
CustomSecurity      : byte: 0x00
EsrtLastAttemptStatus: dword: 0x00000000
EsrtLastAttemptVersion: dword: 0x00000309
FeData              : blob: 406 bytes
H2OFormDialogConfig : byte: 0x00
IP6_CONFIG_IFR_NVDATA: blob: 1592 bytes
KEK                 : blob: 2817 bytes
Lang                : ascii: "eng"
MTC                 : dword: 0x00000000
MemoryOverwriteRequestControl: byte: 0x10
MemoryOverwriteRequestControlLock: byte: 0x00
MpmMmioS3SaveUefiVariable: byte: 0x00
MsdmAddress         : qword: 0x000000005aff2000
NetworkSetup        : byte: 0x02
OfflineUniqueIDEKPub: blob: 256 bytes
OfflineUniqueIDEKPubCRC: dword: 0xcdba62ff
OsIndications       : qword: 0x0000000000000000
PK                  : blob: 1365 bytes
PasswordConfig      : blob: 83 bytes
PhysicalBootOrder   : dword: 0x00010000
PlatformLang        : ascii: "en-US"
RestoreFactoryDefault: byte: 0x00
SecureBootData      : blob: 88 bytes
SecureBootEnforce   : byte: 0x01
SecureFlashInfo     : blob: 14 bytes
SetPcrBanks         : byte: 0x02
Setup               : blob: 750 bytes
Tcg2ConfigInfo      : blob: 10 bytes
Tcg2PhysicalPresence: blob: 16 bytes
Tcg2PhysicalPresenceFlags: dword: 0x00000060
Timeout             : word: 0x0000
TrEEPhysicalPresence: qword: 0x0000000053a80000
TrEEPhysicalPresenceFlags: byte: 0x02
UmaCarveOutDefault  : byte: 0x02
UnlockIDCopy        : blob: 32 bytes
UserVgaSelection    : blob: 72 bytes
VarErrorFlag        : byte: 0xff
WIFI_MANAGER_IFR_NVDATA: blob: 4655 bytes
certdb              : blob: 92 bytes
db                  : blob: 4400 bytes
dbx                 : blob: 20668 bytes

What is the best couse of action to continue to receive UEFI updates?

4 Likes

What is the output of df -h /sys/firmware/efi/efivars/ and ls -lhS /sys/firmware/efi/efivars?

Unless you are dual booting with windows, you can probably remove windows boot entries to make a little bit more space (efibootmgr -B -b 0003 and efibootmgr -B -b 0004). Unless the issue isn’t so much a lack of free space, but a lack of continuous free space.

There’s another thread for the same issue here: Efivars full on Framework 13 AMD 7040 series

1 Like
$ ls -lhS /sys/firmware/efi/efivars
total 0
-rw-r--r--. 1 root root  21K Aug 11 15:57 dbx-d719b2cb-3d3a-4596-a3bc-dad00e67656f
-rw-r--r--. 1 root root  18K Aug 11 15:57 dbxDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root 4.6K Aug 11 15:57 WIFI_MANAGER_IFR_NVDATA-9f94d327-0b18-4245-8ff2-832e300d2cef
-rw-r--r--. 1 root root 4.4K Aug 11 15:57 db-d719b2cb-3d3a-4596-a3bc-dad00e67656f
-rw-r--r--. 1 root root 4.4K Aug 11 15:57 dbDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root 2.8K Aug 11 15:57 KEK-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root 2.8K Aug 11 15:57 KEKDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root 1.7K Aug 11 15:57 AmdSetupPHX-3a997502-647a-4c82-998e-52ef9486a247
-rw-r--r--. 1 root root 1.6K Aug 11 15:57 IP6_CONFIG_IFR_NVDATA-02eea107-98db-400e-9830-460a1542d799
-rw-r--r--. 1 root root 1.4K Aug 11 15:57 PK-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root 1.4K Aug 11 15:57 PKDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root 1.3K Aug 11 15:57 AMD_PBS_SETUP-a339d746-f678-49b3-9fc7-54ce0f9df226
-rw-r--r--. 1 root root 1.2K Aug 11 15:57 MokListRT-605dab50-e046-4300-abb6-3dd810dd8b23
-rw-r--r--. 1 root root  810 Aug 11 15:57 AodSetupPhx-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r--r--. 1 root root  754 Aug 11 15:57 Setup-a04a27f4-df00-4d42-b552-39511302113d
-rw-r--r--. 1 root root  410 Aug 11 15:57 FeData-1f2d63e1-febd-4dc7-9cc5-ba2b1cef9c5b
-rw-r--r--. 1 root root  404 Aug 11 15:57 AodCoreInfo-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r--r--. 1 root root  404 Aug 11 15:57 AodCoreInfoTemp-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r--r--. 1 root root  304 Aug 11 15:57 Boot0003-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root  304 Aug 11 15:57 Boot0004-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root  260 Aug 11 15:57 OfflineUniqueIDEKPub-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r--r--. 1 root root  122 Aug 11 15:57 Boot0000-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root  118 Aug 11 15:57 Boot0001-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root  112 Aug 11 15:57 certdbv-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   96 Aug 11 15:57 certdb-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   92 Aug 11 15:57 SecureBootData-aa1305b9-01f3-4afb-920e-c9b979a852fd
-rw-r--r--. 1 root root   87 Aug 11 15:57 PasswordConfig-f72deef6-13ef-4958-b027-0e45ce7fa45e
-rw-r--r--. 1 root root   80 Aug 11 15:57 MokListXRT-605dab50-e046-4300-abb6-3dd810dd8b23
-rw-r--r--. 1 root root   78 Aug 11 15:57 LoaderDevicePartUUID-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f
-rw-r--r--. 1 root root   76 Aug 11 15:57 UserVgaSelection-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   53 Aug 11 15:57 ConIn-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   53 Aug 11 15:57 ConInCandidateDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   52 Aug 11 15:57 Capsule0000-39b68c46-f7fb-441b-b6ec-16b0f69821f3
-rw-r--r--. 1 root root   50 Aug 11 15:57 SbatLevelRT-605dab50-e046-4300-abb6-3dd810dd8b23
-rw-r--r--. 1 root root   46 Aug 11 15:57 Boot2001-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   44 Aug 11 15:57 Boot2002-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   40 Aug 11 15:57 Boot2003-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   40 Aug 11 15:57 ConOut-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   40 Aug 11 15:57 ConOutCandidateDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   40 Aug 11 15:57 ConOutDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   40 Aug 11 15:57 ErrOutDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   38 Aug 11 15:57 ConInDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   36 Aug 11 15:57 COMPAL-b697de83-1ab6-42c4-9dee-a806c637818b
-rw-r--r--. 1 root root   36 Aug 11 15:57 SignatureSupport-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   36 Aug 11 15:57 UnlockIDCopy-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r--r--. 1 root root   34 Aug 11 15:57 PlatformLangCodes-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   32 Aug 11 15:57 ActiveVgaDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   26 Aug 11 15:57 CapsuleLast-39b68c46-f7fb-441b-b6ec-16b0f69821f3
-rw-r--r--. 1 root root   24 Aug 11 15:57 LoaderInfo-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f
-rw-r--r--. 1 root root   20 Aug 11 15:57 PlugInVgaHandles-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   20 Aug 11 15:57 Tcg2PhysicalPresence-aeb9c5c1-94f1-4d02-bfd9-4602db2d3c54
-rw-r--r--. 1 root root   18 Aug 11 15:57 SecureFlashInfo-382af2bb-ffff-abcd-aaee-cce099338877
-rw-r--r--. 1 root root   17 Aug 11 15:57 LangCodes-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   16 Aug 11 15:57 StatusCodeLog-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   14 Aug 11 15:57 AmdAcpiVar-79941ecd-ed36-49d0-8124-e4c31ac75cd4
-rw-r--r--. 1 root root   14 Aug 11 15:57 BootOrder-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   14 Aug 11 15:57 Tcg2ConfigInfo-07a66697-d400-4903-b3da-67a61d2b7058
-rw-r--r--. 1 root root   12 Aug 11 15:57 AcpiGlobalVariable-c020489e-6db2-4ef2-9aa5-ca06fc11d36a
-rw-r--r--. 1 root root   12 Aug 11 15:57 AMD_RAID-fe26a894-d199-47d4-8afa-070e3d54ba86
-rw-r--r--. 1 root root   12 Aug 11 15:57 IhisiParamBuffer-92e59835-5f42-4e0b-9a84-47c7810ea806
-rw-r--r--. 1 root root   12 Aug 11 15:57 MsdmAddress-fd21bf2b-f5d1-46c5-aee3-c60158339239
-rw-r--r--. 1 root root   12 Aug 11 15:57 OsIndications-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   12 Aug 11 15:57 OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root   12 Aug 11 15:57 TrEEPhysicalPresence-f24643c2-c622-494e-8a0d-4632579c2d5b
-rw-r--r--. 1 root root   10 Aug 11 15:57 CustomPlatformLang-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root   10 Aug 11 15:57 PlatformLang-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root    8 Aug 11 15:57 ApSyncFlagNv-ad3f6761-f0a3-46c8-a4cb-19b70ffdb305
-rw-r--r--. 1 root root    8 Aug 11 15:57 BootOptionSupport-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root    8 Aug 11 15:57 EsrtLastAttemptStatus-b5f7dcc1-568c-50f8-a4dd-e39d1f93fda1
-rw-r--r--. 1 root root    8 Aug 11 15:57 EsrtLastAttemptVersion-b5f7dcc1-568c-50f8-a4dd-e39d1f93fda1
-rw-r--r--. 1 root root    8 Aug 11 15:57 Lang-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root    8 Aug 11 15:57 MTC-eb704011-1402-11d3-8e77-00a0c969723b
-rw-r--r--. 1 root root    8 Aug 11 15:57 OfflineUniqueIDEKPubCRC-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r--r--. 1 root root    8 Aug 11 15:57 PhysicalBootOrder-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root    8 Aug 11 15:57 Tcg2PhysicalPresenceFlags-aeb9c5c1-94f1-4d02-bfd9-4602db2d3c54
-rw-r--r--. 1 root root    6 Aug 11 15:57 BootCurrent-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root    6 Aug 11 15:57 Timeout-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root    5 Aug 11 15:57 AmdVariableProtection-408f573d-65ee-49ed-8bc5-5a32bbeae745
-rw-r--r--. 1 root root    5 Aug 11 15:57 CurrentPolicy-77fa9abd-0359-4d32-bd60-28f4e78f784b
-rw-r--r--. 1 root root    5 Aug 11 15:57 CustomSecurity-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root    5 Aug 11 15:57 H2OFormDialogConfig-98ae8272-ce5a-46be-9f5d-d9f9cbbb99f2
-rw-r--r--. 1 root root    5 Aug 11 15:57 MemoryOverwriteRequestControl-e20939be-32d4-41be-a150-897f85d49829
-rw-r--r--. 1 root root    5 Aug 11 15:57 MemoryOverwriteRequestControlLock-bb983ccf-151d-40e1-a07b-4a17be168292
-rw-r--r--. 1 root root    5 Aug 11 15:57 MokListTrustedRT-605dab50-e046-4300-abb6-3dd810dd8b23
-rw-r--r--. 1 root root    5 Aug 11 15:57 MpmMmioS3SaveUefiVariable-8facafae-6d58-4b36-bf09-e60571b157d2
-rw-r--r--. 1 root root    5 Aug 11 15:57 NetworkSetup-a04a27f4-df00-4d42-b552-39511302113d
-rw-r--r--. 1 root root    5 Aug 11 15:57 RestoreFactoryDefault-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root    5 Aug 11 15:57 SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root    5 Aug 11 15:57 SecureBootEnforce-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r--. 1 root root    5 Aug 11 15:57 SetPcrBanks-8376bdca-5e03-4735-951a-4a74141e5886
-rw-r--r--. 1 root root    5 Aug 11 15:57 SetupMode-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r--. 1 root root    5 Aug 11 15:57 TrEEPhysicalPresenceFlags-f24643c2-c622-494e-8a0d-4632579c2d5b
-rw-r--r--. 1 root root    5 Aug 11 15:57 UmaCarveOutDefault-0e5ce58d-e59b-4f93-904a-6ef2b97a41d7
-rw-r--r--. 1 root root    5 Aug 11 15:57 VarErrorFlag-04b37fe8-f6ae-480b-bdd5-37d98c5e89aa
-rw-r--r--. 1 root root    5 Aug 11 15:57 VendorKeys-8be4df61-93ca-11d2-aa0d-00e098032b8c
$ df -h /sys/firmware/efi/efivars/
Filesystem      Size  Used Avail Use% Mounted on
efivarfs        148K  133K   11K  93% /sys/firmware/efi/efivars

Thanks for linking. Looks like there is nothing super actionable at the moment. Let’s see how the discussion continues to evolve in both threads. Deleting the Windows boot entries would save only 10s of bytes as suggested by @Felix_Pehla. I don’t dual boot for what it’s worth.

What in the end worked for me, was applying it via GNOME Software, which does it via reboot.

can you elaborate? I’m having this same issue and would prefer a simple fix vs a complex one

Start GNOME Software and update your system with it. It will also do firmware updates and does it via reboot and performing the stunt w/o user logged in. This did the trick for me :slight_smile:

I think I just figured this out. I’m on a FW16 running Bazzite, using AMD 7040 and BIOS 3.07. It would appear I fixed it by going into the secure boot admin settings in the UEFI setup, erasing the secure boot settings which erases the whole database. Then after rebooting I went back into the secure boot settings and restored the secure boot settings to default. After doing this I the prompt to update the secure boot database seems to have disappeared. That said, I kinda just fumbled my way through it so I may have created more problems than I solved. Thought I’d drop this here though.

Output after the above steps:

$ fwupdmgr get-updates
Devices with no available firmware updates:
• Hub
• KEK CA
• Option ROM UEFI CA
• SBAT
• SSD 990 PRO 2TB
• Windows UEFI CA
• frame.work-LaptopAMDDB
• frame.work-LaptopAMDKEK
Devices with the latest available firmware version:
• Fingerprint Sensor
• System Firmware
• UEFI CA
• UEFI dbx
No updates available

$ df -h /sys/firmware/efi/efivars/
Filesystem Size Used Avail Use% Mounted on
efivarfs 148K 58K 86K 40% /sys/firmware/efi/efivars

$ ls -lhS /sys/firmware/efi/efivars
total 0
-rw-r–r–. 1 root root 21K Oct 19 23:06 dbx-d719b2cb-3d3a-4596-a3bc-dad00e67656f
-rw-r–r–. 1 root root 21K Oct 19 23:06 dbxDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 8.7K Oct 19 23:06 db-d719b2cb-3d3a-4596-a3bc-dad00e67656f
-rw-r–r–. 1 root root 8.7K Oct 19 23:06 dbDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 4.6K Oct 19 23:06 WIFI_MANAGER_IFR_NVDATA-9f94d327-0b18-4245-8ff2-832e300d2cef
-rw-r–r–. 1 root root 4.3K Oct 19 23:06 KEK-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 4.3K Oct 19 23:06 KEKDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 2.7K Oct 19 23:06 MokListRT-605dab50-e046-4300-abb6-3dd810dd8b23
-rw-r–r–. 1 root root 1.7K Oct 19 23:06 AmdSetupPHX-3a997502-647a-4c82-998e-52ef9486a247
-rw-r–r–. 1 root root 1.6K Oct 19 23:06 IP6_CONFIG_IFR_NVDATA-02eea107-98db-400e-9830-460a1542d799
-rw-r–r–. 1 root root 1.4K Oct 19 23:06 PK-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 1.4K Oct 19 23:06 PKDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 1.3K Oct 19 23:06 AMD_PBS_SETUP-a339d746-f678-49b3-9fc7-54ce0f9df226
-rw-r–r–. 1 root root 810 Oct 19 23:06 AodSetupPhx-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r–r–. 1 root root 754 Oct 19 23:06 Setup-a04a27f4-df00-4d42-b552-39511302113d
-rw-r–r–. 1 root root 540 Oct 19 23:06 PBRDevicePath-a9b5f8d2-cb6d-42c2-bc01-b5ffaae4335e
-rw-------. 1 root root 516 Oct 19 23:06 LoaderSystemToken-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f
-rw-r–r–. 1 root root 410 Oct 19 23:06 FeData-1f2d63e1-febd-4dc7-9cc5-ba2b1cef9c5b
-rw-r–r–. 1 root root 404 Oct 19 23:06 AodCoreInfo-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r–r–. 1 root root 404 Oct 19 23:06 AodCoreInfoTemp-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r–r–. 1 root root 260 Oct 19 23:06 OfflineUniqueIDEKPub-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r–r–. 1 root root 122 Oct 19 23:06 Boot0003-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 118 Oct 19 23:06 Boot0000-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 112 Oct 19 23:06 certdbv-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 96 Oct 19 23:06 certdb-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 96 Oct 19 23:06 SecureBootData-aa1305b9-01f3-4afb-920e-c9b979a852fd
-rw-r–r–. 1 root root 87 Oct 19 23:06 PasswordConfig-f72deef6-13ef-4958-b027-0e45ce7fa45e
-rw-r–r–. 1 root root 84 Oct 19 23:06 ConInDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 80 Oct 19 23:06 MokListXRT-605dab50-e046-4300-abb6-3dd810dd8b23
-rw-r–r–. 1 root root 78 Oct 19 23:06 LoaderDevicePartUUID-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f
-rw-r–r–. 1 root root 76 Oct 19 23:06 UserVgaSelection-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 53 Oct 19 23:06 ConIn-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 53 Oct 19 23:06 ConInCandidateDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 52 Oct 19 23:06 Capsule0000-39b68c46-f7fb-441b-b6ec-16b0f69821f3
-rw-r–r–. 1 root root 50 Oct 19 23:06 SbatLevelRT-605dab50-e046-4300-abb6-3dd810dd8b23
-rw-r–r–. 1 root root 46 Oct 19 23:06 Boot2001-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 44 Oct 19 23:06 Boot2002-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 43 Oct 19 23:06 AUTOPILOT_MARKER-616e2ea6-af89-7eb3-f2ef-4e47368a657b
-rw-r–r–. 1 root root 40 Oct 19 23:06 Boot2003-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 40 Oct 19 23:06 ConOut-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 40 Oct 19 23:06 ConOutCandidateDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 40 Oct 19 23:06 ConOutDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 40 Oct 19 23:06 ErrOutDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 36 Oct 19 23:06 COMPAL-b697de83-1ab6-42c4-9dee-a806c637818b
-rw-r–r–. 1 root root 36 Oct 19 23:06 SignatureSupport-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 36 Oct 19 23:06 UnlockIDCopy-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r–r–. 1 root root 34 Oct 19 23:06 PlatformLangCodes-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 32 Oct 19 23:06 ActiveVgaDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 26 Oct 19 23:06 CapsuleLast-39b68c46-f7fb-441b-b6ec-16b0f69821f3
-rw-r–r–. 1 root root 24 Oct 19 23:06 LoaderInfo-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f
-rw-r–r–. 1 root root 20 Oct 19 23:06 PlugInVgaHandles-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 20 Oct 19 23:06 Tcg2PhysicalPresence-aeb9c5c1-94f1-4d02-bfd9-4602db2d3c54
-rw-r–r–. 1 root root 18 Oct 19 23:06 SecureFlashInfo-382af2bb-ffff-abcd-aaee-cce099338877
-rw-r–r–. 1 root root 17 Oct 19 23:06 LangCodes-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 16 Oct 19 23:06 StatusCodeLog-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 14 Oct 19 23:06 AmdAcpiVar-79941ecd-ed36-49d0-8124-e4c31ac75cd4
-rw-r–r–. 1 root root 14 Oct 19 23:06 BootOrder-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 14 Oct 19 23:06 Tcg2ConfigInfo-07a66697-d400-4903-b3da-67a61d2b7058
-rw-r–r–. 1 root root 12 Oct 19 23:06 AcpiGlobalVariable-c020489e-6db2-4ef2-9aa5-ca06fc11d36a
-rw-r–r–. 1 root root 12 Oct 19 23:06 AMD_RAID-fe26a894-d199-47d4-8afa-070e3d54ba86
-rw-r–r–. 1 root root 12 Oct 19 23:06 IhisiParamBuffer-92e59835-5f42-4e0b-9a84-47c7810ea806
-rw-r–r–. 1 root root 12 Oct 19 23:06 MsdmAddress-fd21bf2b-f5d1-46c5-aee3-c60158339239
-rw-r–r–. 1 root root 12 Oct 19 23:06 OsIndications-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 12 Oct 19 23:06 OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 12 Oct 19 23:06 TrEEPhysicalPresence-f24643c2-c622-494e-8a0d-4632579c2d5b
-rw-r–r–. 1 root root 10 Oct 19 23:06 CustomPlatformLang-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 10 Oct 19 23:06 PlatformLang-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 8 Oct 19 23:06 BootOptionSupport-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 8 Oct 19 23:06 EsrtLastAttemptStatus-6ae76af1-c002-5d64-8e18-658d205acf34
-rw-r–r–. 1 root root 8 Oct 19 23:06 EsrtLastAttemptVersion-6ae76af1-c002-5d64-8e18-658d205acf34
-rw-r–r–. 1 root root 8 Oct 19 23:06 Lang-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 8 Oct 19 23:06 MTC-eb704011-1402-11d3-8e77-00a0c969723b
-rw-r–r–. 1 root root 8 Oct 19 23:06 OfflineUniqueIDEKPubCRC-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r–r–. 1 root root 8 Oct 19 23:06 PhysicalBootOrder-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 8 Oct 19 23:06 Tcg2PhysicalPresenceFlags-aeb9c5c1-94f1-4d02-bfd9-4602db2d3c54
-rw-r–r–. 1 root root 6 Oct 19 23:06 BootCurrent-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 6 Oct 19 23:06 Timeout-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 5 Oct 19 23:06 AmdVariableProtection-408f573d-65ee-49ed-8bc5-5a32bbeae745
-rw-r–r–. 1 root root 5 Oct 19 23:06 CurrentPolicy-77fa9abd-0359-4d32-bd60-28f4e78f784b
-rw-r–r–. 1 root root 5 Oct 19 23:06 CustomSecurity-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 5 Oct 19 23:06 H2OFormDialogConfig-98ae8272-ce5a-46be-9f5d-d9f9cbbb99f2
-rw-r–r–. 1 root root 5 Oct 19 23:06 MemoryOverwriteRequestControl-e20939be-32d4-41be-a150-897f85d49829
-rw-r–r–. 1 root root 5 Oct 19 23:06 MemoryOverwriteRequestControlLock-bb983ccf-151d-40e1-a07b-4a17be168292
-rw-r–r–. 1 root root 5 Oct 19 23:06 MokListTrustedRT-605dab50-e046-4300-abb6-3dd810dd8b23
-rw-r–r–. 1 root root 5 Oct 19 23:06 NetworkSetup-a04a27f4-df00-4d42-b552-39511302113d
-rw-r–r–. 1 root root 5 Oct 19 23:06 RestoreFactoryDefault-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 5 Oct 19 23:06 SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 5 Oct 19 23:06 SecureBootEnforce-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r–r–. 1 root root 5 Oct 19 23:06 SetPcrBanks-8376bdca-5e03-4735-951a-4a74141e5886
-rw-r–r–. 1 root root 5 Oct 19 23:06 SetupMode-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r–r–. 1 root root 5 Oct 19 23:06 TrEEPhysicalPresenceFlags-f24643c2-c622-494e-8a0d-4632579c2d5b
-rw-r–r–. 1 root root 5 Oct 19 23:06 UmaCarveOutDefault-0e5ce58d-e59b-4f93-904a-6ef2b97a41d7
-rw-r–r–. 1 root root 5 Oct 19 23:06 VarErrorFlag-04b37fe8-f6ae-480b-bdd5-37d98c5e89aa
-rw-r–r–. 1 root root 5 Oct 19 23:06 VendorKeys-8be4df61-93ca-11d2-aa0d-00e098032b8c

I also have this issue on the framework 12 on bazzite.

when you say erasing the secure boot settings and restoring to default, does that affect secure boot negatively? i’m having this issue on intel, not AMD.

i followed the steps in this link and once the BIOS was updated, i rebooted and reran a check for updates and the error didn’t show up - How to check the BIOS version on Windows/Linux/BIOS
i know someone else mentioned they’d tried it and it didn’t work, but it did for me. maybe it will for others.