We have moved this BIOS to stable, if you have update 3.06 in beta phase, no need to do any action.
Highlights
- Update AMD PI to 1.0.0.2c.
- Modified the F2 key in the F12 Boot Menu to go to the setup menu instead of the settings menu to allow easier navigation to secure boot settings.
- Added support for the single-ROM BIOS Crisis Recovery feature.
- Implemented a delay in sending the 3A profile to prevent incomplete UCSI PPM command resets during S0 boot transitions.
- Added validation logic to reject invalid USB PD index values.
- Fixed a boot hang issue occurring with specific video encoder cards.
- Resolved an issue where an unidentified UART device appeared in the BIOS, and fixed a bug causing console support to be lost following a BIOS update.
- Fixed an issue where the system was unable to boot from partially locked self-encrypting drives (SEDs)
- Resolved an issue where the iGPU memory size was incorrectly capped at 24 GB on systems populated with 96 GB of system memory
- Security Fixed - CVE-2024-36345, CVE-2024-36343, CVE-2025-54502, CVE-2025-62626
Please note: With BIOS 3.06, you can downgrade to a previous version.
You can check your current BIOS version following the steps here to determine if you are on the latest release.
Subscribing to release notifications
If you want to subscribe to new release notifications you can now opt in through this link to receive an email when we release a new BIOS or driver update for your Framework Desktop.
BIOS Crisis Recovery
At the end of POST, the BIOS hands control off to your operating system. Crisis Recovery is a special alternative mode: instead of booting an OS, the BIOS looks for a firmware update file and re-flashes itself.
This lets the system repair its own firmware after a failed or corrupted BIOS flash, for example if a BIOS update was interrupted by a power loss and the machine no longer boots normally.
When To Use BIOS Crisis Recovery
Use these steps if your system fails to power on to the OS after a BIOS update, shows no display, or you were instructed to perform a BIOS recovery. If your system still boots normally, you do not need this procedure.
How Recovery Is Triggered
If the BIOS detects that its own code in flash memory has been corrupted, it automatically enters Crisis Recovery and begins searching attached storage for a recovery file. You do not need to press anything.
Prepare the Recovery Drive
On a working system:
- Insert the USB flash drive and format it as FAT32. (This erases the drive)
- On the drive, create the folder path \EFI\FWK (an EFI folder, and inside it an FWK folder).
- Copy the recovery file into that FWK folder.(The CAP file can be got from the EFI updater package) The full path should be: \EFI\FWK\Desktop_AMD_Ryzen_AI_Max_300_RECOVERY.fd (The file name is case-sensitive and must match exactly.)
- Double-check the file name is spelled exactly and with the same capitalization as shown above, ending in .fd.
- Safely eject the drive.
Perform the Recovery
On a target system:
- Power off the affected system completely.
- Insert the prepared recovery drive into a USB port on the affected system.
- If the BIOS is corrupted it may enter recovery automatically at power-on.
- The BIOS scans all attached storage (USB and NVMe) for the recovery file in \EFI\FWK, then begins re-flashing. Do not power off or remove the drive during this process. (It may take a few minutes to scan and enter the recovery.)
- Wait for the update to complete and the system to restart. The system should then boot to the operating system normally.
Important!! Once flashing begins, keep the system powered and do not remove the recovery media until the process finishes. Interrupting a BIOS flash can leave the system unbootable.
Downloads
Windows
| Download Link | SHA256 |
|---|---|
| Framework_Desktop_Ryzen_AI_MAX_300_BIOS_3.06.exe | 1D91EDB92766D9252AC0E185C94729B5234935FFA21056DFCCDE9592BCD817C1 |
Please do not interrupt power to your desktop while the update is in progress.
Instructions for Windows Installer:
- Run the .exe.
- Click yes to reboot.
- Wait for the firmware progress bar to complete, and then the system will reboot.
Linux/LVFS
Please note that you must update with a charger attached, then run::
fwupdmgr refresh --force
then
fwupdmgr get-updates
then
fwupdmgr update
Linux/Other/UEFI Shell update
| Download Link | SHA256 |
|---|---|
| Framework_Desktop_Ryzen_AI_MAX_300_BIOS_3.06_EFI.zip | 68C251BF20B98C9D0928DDAD51DD920A3B073AA4E1C8BE55FF43454B8B38C013 |
Note that if you use the EFI shell update with Windows, you should suspend Bitlocker if enabled before updating using the EFI updater.
Please do not interrupt power to your desktop while the update is in progress.
Instructions for EFI shell update:
- Extract contents of zip folder to a FAT32 formatted USB drive. Cleanly unmount the drive before physically removing it, otherwise the BIOS update may not function correctly.
- Set the ESP flag for the FAT32 partition.
- Boot your system while pressing F12 and boot from the thumb drive.
- Let startup.nsh run automatically.
- Follow the instructions to install the update.
Security Fixes
| CVE | Note | Score (CVSS Version 4.0) |
|---|---|---|
| CVE-2026-6726 | An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010. | 7.9 |
| CVE-2025-62626 | Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values. | 7.2 |
| CVE-2025-54502 | Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution. | 7.1 |
| CVE-2026-6727 | A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011. | 5.9 |
| CVE-2024-36345 | Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality. | 4.6 |
| CVE-2024-36343 | libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. | N/A |
Enhancements
- Update AMD PI to 1.0.0.2c.
- Added support for the single-ROM BIOS Crisis Recovery feature.
- Modified the F2 key in the F12 Boot Menu to go to the setup menu instead of the settings menu to allow easier navigation to secure boot settings.
- Implemented a delay in sending the 3A profile to prevent incomplete UCSI PPM command resets during S0 boot transitions.
- Added validation logic to reject invalid USB PD index values.
Fixes
- Fixed a boot hang issue occurring with specific video encoder cards.
- Resolved an issue where an unidentified UART device appeared in the BIOS, and fixed a bug causing console support to be lost following a BIOS update.
- Fixed an issue where the system was unable to boot from partially locked self-encrypting drives (SEDs)
- Resolved an issue where the iGPU memory size was incorrectly capped at 24 GB on systems populated with 96 GB of system memory
Component Versions
This BIOS update is a bundle of updates to multiple embedded components in the system.
Not all of them use the same version number.
| Firmware | Version | Updated? |
|---|---|---|
| BIOS | 3.06 | Updated |
| EC | ec_306_bb3566e | Updated |
| PD | 0.0.0E | Same |
| AMD PI | StrixHaloPI-FP11 1.0.0.2c | Updated |
Reporting Issues
To report issues we have created a public issue tracker on github. Issues · FrameworkComputer/SoftwareFirmwareIssueTracker · GitHub We hope that this is a better way to track issues with community involvement moving forward as we have found it difficult to both gather relevant information about issues people are reporting on the forums, and track the issues through their lifecycle in a transparent way.
If you do experience an issue with the update that is related to your system firmware, please post as complete a description as you can, including relevant system information, and external peripherals. Please note that we do not currently have a SLA for responding to issues on github, but we will be reviewing them through the bios release process, and will review them for future updates as well.
If you have an issue regarding hardware, broken devices, returns, etc, this is not the place, please contact support.
Known Issues
- Certain USB-C peripherals may exhibit intermittent compatibility issues during the PD or DisplayPort Alt Mode handshake.