Weird message after enabling Secure Boot

Hello,

I’m on a Framework 13 with Bazzite OS. I decided to enable Secure Boot some time last week, and now when I do a System Update while using Bazzite’s desktop, I see the message below, what does it mean? Anything I should be concerned about?


Updating lvfs
Downloading… [***************************************]
Successfully downloaded new metadata:
• 9 devices are updatable
• 4 devices are supported in the enabled remotes (an update has been published)
Devices with no available firmware updates:
• WD BLACK SN850X 1000GB
• KEK CA
• Option ROM UEFI CA
• SBAT
• Windows UEFI CA
• frame.work-LaptopAMDDB
• frame.work-LaptopAMDKEK
Devices with the latest available firmware version:
• System Firmware
• Fingerprint Sensor
• UEFI CA
Framework Laptop 13 (AMD Ryzen 7040Series)

└─UEFI dbx:
│ Device ID: 362301da643102b9f38477387e2193e57abaa590
│ Summary: UEFI revocation database
│ Current version: 20250507
│ Minimum Version: 20250507
│ Vendor: Microsoft (UEFI:Microsoft)
│ Install Duration: 1 second
│ GUIDs: f8ba2887-9411-5c36-9cee-88995bb39731 ← UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64
│ d07ff664-b0e1-5f4e-a723-d7fbcbfcb94f ← UEFI\CRT_3CD3F0309EDAE228767A976DD40D9F4AFFC4FBD5218F2E8CC3C9DD97E8AC6F9D&ARCH_X64
│ 115f7cac-f705-5d34-9a47-37177c3e8514 ← UEFI\CRT_B38FAD316F525F27B27A21B486456C3E4279748BF16893827BF16FE659C0F75E&ARCH_X64
│ Device Flags: • Internal device
│ • Updatable
│ • Supported on remote server
│ • Needs a reboot after installation
│ • Device is usable for the duration of the update
│ • Only version upgrades are allowed
│ • Signed Payload
│ • Can tag for emulation

└─Secure Boot dbx Configuration Update:
New version: 20250902
Remote ID: lvfs
Release ID: 130035
Summary: UEFI Secure Boot Forbidden Signature Database
Variant: x64
License: Proprietary
Size: 24.1 kB
Created: 2025-09-02 00:00:00
Urgency: High
Tested: 2026-06-08 00:00:00
Distribution: ubuntu 26.04
Old version: 20230501
Version[fwupd]: 2.1.1
Tested: 2026-05-29 00:00:00
Distribution: debian 13
Old version: 20250507
Version[fwupd]: 2.0.20
Tested: 2026-04-20 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.16
Tested: 2026-02-25 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.18
Tested: 2026-02-13 00:00:00
Distribution: ubuntu 25.10
Old version: 20230501
Version[fwupd]: 2.0.17
Tested: 2025-12-05 00:00:00
Distribution: fedora 42 (workstation)
Old version: 20250507
Version[fwupd]: 2.0.17
Tested: 2025-11-10 00:00:00
Distribution: fedora 43 (kde)
Old version: 20230501
Version[fwupd]: 2.0.16
Vendor: Linux Foundation
Duration: 1 second
Release Flags: • Trusted metadata
• Is upgrade
• Tested by trusted vendor
Description:
This updates the list of forbidden signatures (the “dbx”) to the latest release from Microsoft.

    Some insecure versions of the IGEL bootloader were added, due to a security vulnerability that allowed an attacker to bypass UEFI Secure Boot.
    Issue:            CVE-2025-47827
    Checksum:         7178302fa23fcb875e7540900e299fb30a76758663efb7e1c56edc25cd3f316a

Hi, I think they simply found a security flaw and fixed it with the update. I think it was something that could have allowed a virus to boot before the operating system. In any case, I don’t think you need to worry. I just recommend always restarting your laptop after an update.

Oh, i see what it is.

UEFI bioses can only apply secure boot updates when secure boot is enabled, it’s just updated the secure boot certificate databases, this is to ensure update integrity.

yes, exactly

Ok thank you both! The message is still there after a restart, but if there is nothing to worry about I’ll just ignore it. But I’d also appreciate if anyone knows of a way of making it go away.