Hello,
I’m on a Framework 13 with Bazzite OS. I decided to enable Secure Boot some time last week, and now when I do a System Update while using Bazzite’s desktop, I see the message below, what does it mean? Anything I should be concerned about?
Updating lvfs
Downloading… [***************************************]
Successfully downloaded new metadata:
• 9 devices are updatable
• 4 devices are supported in the enabled remotes (an update has been published)
Devices with no available firmware updates:
• WD BLACK SN850X 1000GB
• KEK CA
• Option ROM UEFI CA
• SBAT
• Windows UEFI CA
• frame.work-LaptopAMDDB
• frame.work-LaptopAMDKEK
Devices with the latest available firmware version:
• System Firmware
• Fingerprint Sensor
• UEFI CA
Framework Laptop 13 (AMD Ryzen 7040Series)
│
└─UEFI dbx:
│ Device ID: 362301da643102b9f38477387e2193e57abaa590
│ Summary: UEFI revocation database
│ Current version: 20250507
│ Minimum Version: 20250507
│ Vendor: Microsoft (UEFI:Microsoft)
│ Install Duration: 1 second
│ GUIDs: f8ba2887-9411-5c36-9cee-88995bb39731 ← UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64
│ d07ff664-b0e1-5f4e-a723-d7fbcbfcb94f ← UEFI\CRT_3CD3F0309EDAE228767A976DD40D9F4AFFC4FBD5218F2E8CC3C9DD97E8AC6F9D&ARCH_X64
│ 115f7cac-f705-5d34-9a47-37177c3e8514 ← UEFI\CRT_B38FAD316F525F27B27A21B486456C3E4279748BF16893827BF16FE659C0F75E&ARCH_X64
│ Device Flags: • Internal device
│ • Updatable
│ • Supported on remote server
│ • Needs a reboot after installation
│ • Device is usable for the duration of the update
│ • Only version upgrades are allowed
│ • Signed Payload
│ • Can tag for emulation
│
└─Secure Boot dbx Configuration Update:
New version: 20250902
Remote ID: lvfs
Release ID: 130035
Summary: UEFI Secure Boot Forbidden Signature Database
Variant: x64
License: Proprietary
Size: 24.1 kB
Created: 2025-09-02 00:00:00
Urgency: High
Tested: 2026-06-08 00:00:00
Distribution: ubuntu 26.04
Old version: 20230501
Version[fwupd]: 2.1.1
Tested: 2026-05-29 00:00:00
Distribution: debian 13
Old version: 20250507
Version[fwupd]: 2.0.20
Tested: 2026-04-20 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.16
Tested: 2026-02-25 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.18
Tested: 2026-02-13 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.17
Tested: 2025-12-05 00:00:00
Distribution: fedora 42 (workstation)
Old version: 20250507
Version[fwupd]: 2.0.17
Tested: 2025-11-10 00:00:00
Distribution: fedora 43 (kde)
Old version: 20230501
Version[fwupd]: 2.0.16
Vendor: Linux Foundation
Duration: 1 second
Release Flags: • Trusted metadata
• Is upgrade
• Tested by trusted vendor
Description:
This updates the list of forbidden signatures (the “dbx”) to the latest release from Microsoft.
Some insecure versions of the IGEL bootloader were added, due to a security vulnerability that allowed an attacker to bypass UEFI Secure Boot.
Issue: CVE-2025-47827
Checksum: 7178302fa23fcb875e7540900e299fb30a76758663efb7e1c56edc25cd3f316a