< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Fwupd 2.1.7 Release Patches Critical Linux Firmware Vulnerability and Adds UEFI Security Features

The fwupd 2.1.7 update for Linux has been released, addressing a trust‑boundary vulnerability (GHSA‑9f42‑c37j‑25jh) that allowed unsigned metadata to bypass authorization checks during firmware installation. The patch delays metadata consumption until trust validation completes and blocks forced installations over D‑Bus.

The new release also introduces a systemd‑pcrlock plugin that integrates with UEFI firmware update flows, adds Hardware Security Index attributes for SPI flash lock status and TCG‑compatible disk encryption, expands support for externally managed EFI signature lists, and provides AppStream identifiers for common BIOS settings. Additional bug fixes cover hardware compatibility (Lenovo TBT5 Smart Dock, Dell docks, Logitech HID++ bootloader), policy‑kit errors, and memory‑safety issues across several core plugins.

Entities

Daniel Birtwhistle · Linux · Richard Hughes · fwupd · systemd-pcrlock

Sources

about 2 months ago