fwupd 2.1.8 Adds a bootupd Plugin, New Docks and Fingerprint Readers, and Updated DBX Hashes
fwupd 2.1.8, the daemon behind firmware updates on almost every Linux desktop, was released on September 24.
New hardware
- ASUS GX5407
- Elan fingerprint reader PID 0CB6
- FocalTech MOC fingerprint sensors
- Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 (7000 series)
- MaxLinear MxL862xx network switches
- MediaTek MT9700 FCTE and MT9701 KSMU
- Additional Pixart devices
- Rolling Wireless RW101 modules
New features
A bootupd plugin. bootupd is the tool image-based systems like Fedora CoreOS and the Atomic desktops use to update the bootloader on the EFI System Partition. fwupd now coordinates with it, so the two do not step on each other when both want to change the ESP.
Updated DBX hashes. The DBX is the UEFI revocation list: hashes of bootloaders that Secure Boot must refuse to run. fwupd ships these so offline machines can still receive revocations. Our Secure Boot explainer covers why the DBX matters and why its updates occasionally make old boot media stop working.
Also new: RSA-3072 signature verification for Lenovo accessories, clearer messages about who is logged in when a Dell dock update needs attention, and a workaround for systemd-pcrosseparator.service extending PCR0, which could otherwise upset TPM-sealed secrets. If you unlock your disk with the TPM, our TPM LUKS unlock guide explains why PCR changes matter.
Hardening and fixes
- A buffer overwrite when parsing Synaptics CAPE HID reports
- Memory leaks in TPM event log parsing, and file descriptor leaks
- Firmware recovery for Logitech Unifying receivers
- Stricter UEFI capsule index parsing and a 2 GiB cap on LZMA decompression
- Redfish firmware blobs can now be up to 512 MiB, and BIOS settings enumeration improved
Updating firmware
fwupdmgr refresh
fwupdmgr get-updates
fwupdmgr update
Our firmware updates guide covers fwupd, the LVFS, and CPU microcode in more depth.