⇦ | fwupd [main]
Last updated on: 2026-08-27 16:42 [UTC]

Metadata for fwupd in main

org.freedesktop.fwupd - 2.0.20-1~bpo13+1 ⚙ riscv64

Icon
---
Type: console-application
ID: org.freedesktop.fwupd
Package: fwupd
ProjectLicense: LGPL-2.0+
Name:
  C: fwupd
Summary:
  C: Update device firmware on Linux
Description:
  C: >-
    <p>This project aims to make updating firmware on Linux automatic, safe and reliable. You can either use a GUI software manager like
    GNOME Software to view and apply updates, the command-line tool or the D-Bus interface directly.</p>
    
    <p>The fwupd process is a system daemon to allow session software to update device firmware on your local machine. It is designed
    for desktops, but this project is also usable on phones, tablets and on headless servers.</p>
Developer:
  id: org.fwupd
  name:
    C: The fwupd authors
Url:
  bugtracker: https://github.com/fwupd/fwupd/issues
  homepage: https://fwupd.org/
  translate: https://hosted.weblate.org/projects/fwupd/fwupd/
  vcs-browser: https://github.com/fwupd/fwupd
Provides:
  binaries:
  - fwupdmgr
  - fwupdtool
Languages:
- locale: ar
  percentage: 100
- locale: bg
  percentage: 95
- locale: ca
  percentage: 98
- locale: cs
  percentage: 99
- locale: da
  percentage: 52
- locale: de
  percentage: 100
- locale: en_GB
  percentage: 100
- locale: en_US
  percentage: 100
- locale: es
  percentage: 98
- locale: eu
  percentage: 26
- locale: fi
  percentage: 98
- locale: fr
  percentage: 33
- locale: fur
  percentage: 43
- locale: he
  percentage: 46
- locale: hi
  percentage: 88
- locale: hr
  percentage: 94
- locale: hu
  percentage: 84
- locale: id
  percentage: 93
- locale: it
  percentage: 76
- locale: ja
  percentage: 99
- locale: ka
  percentage: 39
- locale: ko
  percentage: 84
- locale: lt
  percentage: 47
- locale: nl
  percentage: 44
- locale: pl
  percentage: 95
- locale: pt
  percentage: 55
- locale: pt_BR
  percentage: 100
- locale: ro
  percentage: 100
- locale: ru
  percentage: 46
- locale: si
  percentage: 62
- locale: sl
  percentage: 100
- locale: sv
  percentage: 100
- locale: tr
  percentage: 45
- locale: uk
  percentage: 99
- locale: zh_CN
  percentage: 54
- locale: zh_TW
  percentage: 52
Releases:
- version: "2.0.20"
  type: stable
  unix-timestamp: 1772064000
  description:
    C: >-
      <p>This release adds the following features:</p>
      
      <ul>
        <li>Add support for changing AMD UMA carveout size</li>
        <li>Warn the user if they are using the blocked-firmware functionality</li>
      </ul>
      
      <p>This release fixes the following bugs:</p>
      
      <ul>
        <li>Disable the UEFI plugins on 32bit x86</li>
        <li>Do not hang when parsing an invalid USB descriptor</li>
        <li>Do not return an error if the fastboot property is not provided</li>
        <li>Fix a CCGX DMC regression when installing on the HP G5 dock</li>
        <li>Fix a harmless heap OOB read in AMD kria SOM EEPROM parser</li>
        <li>Fix a potential fastboot string over-read</li>
        <li>Fix a regression causing MBIM QDU updates to fail</li>
        <li>Honor polkit auth for emulation tag modify device</li>
        <li>Speed up calculating the cab checksum by ~21%</li>
        <li>Verify the uncompressed size when decompressing CAB files</li>
      </ul>
      
      <p>This release adds support for the following hardware:</p>
      
      <ul>
        <li>HP Engage One G2 Advanced Hub</li>
        <li>PixArt PJP274 (Framework Laptop)</li>
        <li>Several new Jabra GNP devices</li>
      </ul>
- version: "2.0.19"
  type: stable
  unix-timestamp: 1766102400
  description:
    C: >-
      <p>This release adds the following features:</p>
      
      <ul>
        <li>Add two commands to fwupdtool to calculate and find CRCs</li>
        <li>Allow systems to use the udev event source without using systemd</li>
      </ul>
      
      <p>This release fixes the following bugs:</p>
      
      <ul>
        <li>Always show the correct new firmware version in 'fwupdmgr get-history'</li>
        <li>Fix an integer underflow when parsing a malicious PE file</li>
        <li>Fix a regression when enumerating the dell-dock status component</li>
        <li>Fix the fuzzer timeout when parsing a synaptics-rmi SBL container</li>
        <li>Fix updating the Intel GPU FWDATA section</li>
        <li>Respect 'fwupdmgr --force' when installing firmware</li>
      </ul>
      
      <p>This release adds support for the following hardware:</p>
      
      <ul>
        <li>Lenovo Sapphire Folio Keyboard</li>
      </ul>
- version: "2.0.18"
  type: stable
  unix-timestamp: 1764547200
  description:
    C: >-
      <p>This release adds the following features:</p>
      
      <ul>
        <li>Add a MOTD message for devices needing reboot after staged updates</li>
        <li>Create the reboot-required file when a firmware update requires reboot</li>
        <li>Record the system state for each composite emulation</li>
        <li>Update USI docking station firmware without requiring a manual replug</li>
      </ul>
      
      <p>This release fixes the following bugs:</p>
      
      <ul>
        <li>Add a MTD device problem if the Intel SPI BIOS lock is set</li>
        <li>Allow changing the child name when using PARENT_NAME_PREFIX</li>
        <li>Allow UpdateCapsule to work on systems that do not support SecureBoot</li>
        <li>Correctly parse the EFI_CAPSULE_RESULT_VARIABLE_HEADER</li>
        <li>Fall back to the SMBIOS version for BIOS MTD devices</li>
        <li>Fix a crash when trying to record an i2c emulation</li>
        <li>Fixed Huddly upgrade problems with major version changes</li>
        <li>Fix man page compatibility with apropos and whatis</li>
        <li>Fix parsing USB BOS descriptors</li>
        <li>Fix up the x86_64-specific capsule flags when deploying UEFI firmware</li>
        <li>Improve firmware stream searching speed by a huge amount</li>
        <li>Only convert the release uint32_t to device version format for UEFI devices</li>
        <li>Only handle SIGINT in fwupdtool when required</li>
        <li>Refactor the hypervisor and container detection to be usable from plugins</li>
        <li>Set PlatformArchitecture as the CPU architecture for RISC-V machines</li>
        <li>Use a sensible timeout when doing qc-s5gen2 HID requests</li>
      </ul>
      
      <p>This release adds support for the following hardware:</p>
      
      <ul>
        <li>HP Portable USB-C 4K HDMI Hub</li>
        <li>Lenovo Legion Go 2 (as a HID device)</li>
        <li>Synaptics HapticsPad</li>
      </ul>
- version: "2.0.17"
  type: stable
  unix-timestamp: 1762300800
  description:
    C: >-
      <p>This release adds the following features:</p>
      
      <ul>
        <li>Add support for client-side phased update deployment</li>
        <li>Add support for post-quantum signatures</li>
        <li>Allow clearing the cache dirirectory</li>
        <li>Allow fwupdtpmevlog to dump the raw eventlog data</li>
        <li>Build a NVMe GUID derived from the serial number</li>
        <li>Make fwupdtool extract work with deeply nested images</li>
        <li>Parse VSS and FTW variable stores from EFI volumes</li>
        <li>Reintroduce the FreeBSD CI target</li>
        <li>Support very old versions of UDisks</li>
      </ul>
      
      <p>This release fixes the following bugs:</p>
      
      <ul>
        <li>Add 'fwupdmgr hwids' by exposing another daemon property</li>
        <li>Add offline hashes for the Microsoft 20250902 dbx</li>
        <li>Add the Framework-specific KEK and db hashes</li>
        <li>Allow updating IFD BIOS region via parent MTD</li>
        <li>Avoid showing reinstall prompts for composite devices</li>
        <li>Clean up the fwupdtool lock file in all cases</li>
        <li>Correctly match the correct historical composite component</li>
        <li>Do not allow PK or KEK updates when system has a test key installed</li>
        <li>Do not allow reinstalling when using ONLY_VERSION_UPGRADE</li>
        <li>Do not require AC power to run the installed tests</li>
        <li>Do not scan EFI volumes when constructing MTD BIOS devices</li>
        <li>Ensure REGION is always set for MTD IFD children</li>
        <li>Ensure SCSI instance IDs are valid ASCII values</li>
        <li>Fix a critical warning when parsing invalid Jabra firmware</li>
        <li>Fix an Ilitek parsing crash found when fuzzing</li>
        <li>Fix an inotify race when refreshing metadata</li>
        <li>Fix a pending-activation problem with Dell docking stations</li>
        <li>Fix a potential hang when creating a chunk array with aligned sizes</li>
        <li>Fix MTD emulation recording for PCI-backed devices</li>
        <li>Fix the device order when the parent specifies install-parent-first</li>
        <li>Fix the FLMSTR layout when reading IFD partitions</li>
        <li>Fix the thunderbolt controller rushing to finalize before onlining retimers</li>
        <li>Fix writing Intel GPU OptionROM data and OptionROM code</li>
        <li>Flush stale events to make the Logitech Rallybar more reliable</li>
        <li>Ignore all the Intel GPU MTD devices</li>
        <li>Ignore errors when writing the last page of Dell dock firmware</li>
        <li>Make an error message more specific</li>
        <li>Modify the Dell dock needs-activation flag after updates are installed</li>
        <li>Only add one devlink device for each PCI card</li>
        <li>Parse the FMAP SBOM area as uSWID when required</li>
        <li>Relax the USI dock DMC child device checks for new firmware</li>
        <li>Revert back to the flashrom deprecated API as the new API is unusable</li>
        <li>Rewrite the fwupdmgr manpage to be more useful</li>
        <li>Use higher delay when update status for Logitech peripheral devices</li>
      </ul>
      
      <p>This release adds support for the following hardware:</p>
      
      <ul>
        <li>ASUS CX9406 (touch controller)</li>
        <li>Framework Copilot keyboard</li>
        <li>Genesys GL352530 and GL352360</li>
        <li>Huddly C1</li>
        <li>Lexar and Maxio NVMe SSDs</li>
        <li>Primax Ryder mouse 2</li>
      </ul>
ContentRating:
  oars-1.1:
    social-info: moderate

org.freedesktop.fwupd - 2.1.7-4~bpo13+1 ⚙ amd64 ⚙ arm64 ⚙ armhf ⚙ ppc64el ⚙ s390x

Icon
---
Type: console-application
ID: org.freedesktop.fwupd
Package: fwupd
ProjectLicense: LGPL-2.0+
Name:
  C: fwupd
Summary:
  C: Update device firmware on Linux
Description:
  C: >-
    <p>This project aims to make updating firmware on Linux automatic, safe and reliable. You can either use a GUI software manager like
    GNOME Software to view and apply updates, the command-line tool or the D-Bus interface directly.</p>
    
    <p>The fwupd process is a system daemon to allow session software to update device firmware on your local machine. It is designed
    for desktops, but this project is also usable on phones, tablets and on headless servers.</p>
Developer:
  id: org.fwupd
  name:
    C: The fwupd authors
Url:
  bugtracker: https://github.com/fwupd/fwupd/issues
  homepage: https://fwupd.org/
  translate: https://hosted.weblate.org/projects/fwupd/fwupd/
  vcs-browser: https://github.com/fwupd/fwupd
Provides:
  binaries:
  - fwupdmgr
  - fwupdtool
Languages:
- locale: ar
  percentage: 97
- locale: bg
  percentage: 86
- locale: ca
  percentage: 89
- locale: cs
  percentage: 100
- locale: da
  percentage: 49
- locale: de
  percentage: 100
- locale: en_GB
  percentage: 100
- locale: en_US
  percentage: 100
- locale: es
  percentage: 100
- locale: et
  percentage: 58
- locale: fi
  percentage: 98
- locale: fr
  percentage: 35
- locale: fur
  percentage: 45
- locale: he
  percentage: 43
- locale: hi
  percentage: 80
- locale: hr
  percentage: 85
- locale: hu
  percentage: 76
- locale: id
  percentage: 100
- locale: it
  percentage: 69
- locale: ja
  percentage: 93
- locale: ka
  percentage: 36
- locale: kk
  percentage: 93
- locale: ko
  percentage: 77
- locale: lt
  percentage: 43
- locale: nl
  percentage: 41
- locale: pl
  percentage: 100
- locale: pt
  percentage: 100
- locale: pt_BR
  percentage: 100
- locale: ro
  percentage: 100
- locale: ru
  percentage: 100
- locale: si
  percentage: 55
- locale: sl
  percentage: 100
- locale: sq
  percentage: 93
- locale: sr
  percentage: 93
- locale: sv
  percentage: 100
- locale: tr
  percentage: 48
- locale: uk
  percentage: 98
- locale: zh_CN
  percentage: 99
- locale: zh_TW
  percentage: 58
Releases:
- version: "2.1.7"
  type: stable
  unix-timestamp: 1785110400
  description:
    C: >-
      <p>This release adds the following features:</p>
      
      <ul>
        <li>Add "well known" AppStream IDs for common BIOS settings</li>
        <li>Add MTD lock security attribute</li>
        <li>Add support for "externally managed" EFI signature lists</li>
        <li>Add systemd-pcrlock plugin and hook up to UEFI updates</li>
        <li>Add TCG disk encryption security attribute</li>
        <li>Enable more plugins when compiling for Android</li>
      </ul>
      
      <p>This release fixes the following bugs:</p>
      
      <ul>
        <li>Add wrappers for input streams for future Rust implementations</li>
        <li>Allow overriding some methods in FwupdClient for a future refactor</li>
        <li>Allow plain string versions for some AMD GPUs</li>
        <li>Allow suspend-to-ram with encrypted RAM</li>
        <li>Always test Dell dock type when connected</li>
        <li>Avoid possible out-of-bounds read in when parsing the DFU sector</li>
        <li>Do not abort when udisks cannot resolve a device</li>
        <li>Do not allow force installs over D-Bus</li>
        <li>Do not fail to start when a pre-group comment has no keys set</li>
        <li>Fall back to copying the file descriptor contents when not sealed</li>
        <li>Fix dropped status updates during updates</li>
        <li>Fix FW update for Lenovo TBT5 Smart Dock 7500</li>
        <li>Fix fwupd-refresh.service polkit auth errors</li>
        <li>Fix segfault parsing some logitech-hidpp bootloader records</li>
        <li>Fix the seal self tests when building on a tmpfs</li>
        <li>Fix update failure when the TP IC is in bootloader-only mode</li>
        <li>Mark Coreboot VBOOT as obsoleting BootGuard verified</li>
        <li>Move more per-class limits to the class instances to reduce RSS</li>
        <li>Prepare modem-manager firmware after firehose detach</li>
        <li>Reject out-of-range CCGX device mode before indexing versions</li>
        <li>Require trusted metadata for device updates</li>
        <li>Require trusted metadata when using OnlyTrusted</li>
        <li>Skip modem-manager secboot status when unsupported</li>
        <li>Use safe reads for synaptics-rmi device responses</li>
        <li>Validate GUID-defined section offset against EFI section size</li>
      </ul>
      
      <p>This release adds support for the following hardware:</p>
      
      <ul>
        <li>PixArt PJP360 device</li>
      </ul>
- version: "2.1.6"
  type: stable
  unix-timestamp: 1782864000
  description:
    C: >-
      <p>This release adds the following features:</p>
      
      <ul>
        <li>Add --filter-protocol to fwupdmgr and fwupdtool</li>
        <li>Add a new HSI attribute for coreboot verified boot</li>
        <li>Add hashes for the latest DBX for offline machines</li>
        <li>Allow parsing Hayden Bridge Thunderbolt firmware</li>
        <li>Handle HPE Redfish reset-required updates</li>
        <li>Ignore efivar free space on VMWare, GCE and EC2 VMs</li>
        <li>Prevent FwupdClient from downloading the same file multiple times</li>
        <li>Split UEFI Memory Protection HSI from NX Compat</li>
      </ul>
      
      <p>This release fixes the following bugs:</p>
      
      <ul>
        <li>Avoid an integer overflow in the ifwi-cpd manifest length check</li>
        <li>Avoid truncating the AMD Kria FRU board area offset</li>
        <li>Block dbx updates on ASUSTeK GL553VD</li>
        <li>Check SMEE hardware bit directly for AMD SME detection</li>
        <li>Create the ESP OS directory if not found</li>
        <li>Detect the BCR device on Celeron LPC SPI controllers</li>
        <li>Fall back to a binary firmware when no specific MTD image type is set</li>
        <li>Fix AI table clear behavior of the elantp boot code.</li>
        <li>Fix errors with fwupd-refresh service not working properly</li>
        <li>Fix Genesys GL32xx device locker crash due to argument mismatch</li>
        <li>Fix installing KEK updates when using snapd by sending the correct blob</li>
        <li>Fix integer underflow when Elan firmware is smaller than one page</li>
        <li>Fix possible NULL pointer dereference when updating SteelSeries firmware</li>
        <li>Fix the display of the HP UEFI db certificate</li>
        <li>Improved usi-dock progress reporting behavior</li>
        <li>Increase the parser item limit from 100 to 1000 for large KEKs</li>
        <li>Log out of the Redfish session when required on HPE hardware</li>
        <li>Only show 'authenticating' after a short delay</li>
        <li>Re-process the device metadata when required after all devices are added</li>
        <li>Require sealed memfd input to prevent possible TOCTOU attacks</li>
        <li>Sanitize the Jabra GNP device version in a more secure way</li>
        <li>Validate raydium-tp buffer size before direct index access</li>
        <li>Validate that Lenovo dock device-reported program sizes are valid</li>
      </ul>
      
      <p>This release adds support for the following hardware:</p>
      
      <ul>
        <li>Lenovo dual-bank accessory dongle and paired peripherals</li>
      </ul>
- version: "2.1.5"
  type: stable
  unix-timestamp: 1780963200
  description:
    C: >-
      <p>This release adds the following features:</p>
      
      <ul>
        <li>Allow overriding the detected CPU vendor to allow more self tests</li>
        <li>Allow updating the Windows-specific UEFI CA on dual boot machines</li>
        <li>Install the db updates on broken hardware with new firmware</li>
      </ul>
      
      <p>This release fixes the following bugs:</p>
      
      <ul>
        <li>Add tests for the vbe, upower, uefi-sbat, pci-bcr, mtd, gpio and msr plugins</li>
        <li>Check the array index in some runtime-generated code</li>
        <li>Claim the udev netlink backend before old libusb versions</li>
        <li>Expand the netlink socket buffer to prevent packet loss during event floods</li>
        <li>Fix a msgpack regression when updating some Huddly cameras</li>
        <li>Fix HID feature read buffer size in goodix-tp device probe</li>
        <li>Fix reproducible builds</li>
        <li>Fix the check-reboot-needed command</li>
        <li>Increase the i2c-hid re-bind delay for synaptics-rmi PID 0x96e7</li>
        <li>Parse the dell-dock marketing name in a more safe way</li>
        <li>Set a firmware size limit on intel-gsc aux and oprom firmware types</li>
        <li>Simplify the engine by only loading the config object once</li>
        <li>Use a cryptographically secure RNG when building the idle and inhibit IDs</li>
        <li>Use a more appropriate firmware maximum size for Huddly cameras</li>
      </ul>
      
      <p>This release adds support for the following hardware:</p>
      
      <ul>
        <li>Elan touchscreens</li>
      </ul>
- version: "2.1.4"
  type: stable
  unix-timestamp: 1780012800
  description:
    C: >-
      <p>This release adds the following features:</p>
      
      <ul>
        <li>Add a libcrypto-based JCat implementation for Android</li>
        <li>Add support for NixOS to the quickstart script</li>
        <li>Add support for the Compal BIOS version format</li>
        <li>Allow a remote to specify that a username or password is required</li>
        <li>Allow storing a per-user password in XDG_CONFIG_HOME</li>
        <li>Detect encrypted swap devices below device-mapper</li>
        <li>Ensure that all firmware subclasses set the maximum size</li>
        <li>Remove the flashrom plugin</li>
        <li>Save the SMBIOS BiosReleaseDate string to uploaded reports</li>
        <li>Tell Star Labs coreboot users to manually update when required</li>
      </ul>
      
      <p>This release fixes the following bugs:</p>
      
      <ul>
        <li>Add a retry limit when updating failing Goodix MoC devices</li>
        <li>Add several bounds checks for when updating Dell docks</li>
        <li>Add vendor name and name for the various Framework UEFI certificates</li>
        <li>Allow recovery if the Lenovo dock internal state is invalid</li>
        <li>Avoid trunctaion when calculating the AMD GPU atombios size</li>
        <li>Check firmware size against Novatek flash start address</li>
        <li>Check for config offset overflow when updating Synaptics RMI devices</li>
        <li>Check for multiplication overflow in BCM57xx stage1 size calculation</li>
        <li>Check for overflow when writing to CCGX DMC devices</li>
        <li>Check stream size before calculating Legion HID ID offset</li>
        <li>Check stream size before subtracting Ilitek ITS CRC length</li>
        <li>Clear Sunplus camera download state if the previous flash failed</li>
        <li>Do not show plugin warnings when using --version</li>
        <li>Filter the install flags provided by the D-Bus client</li>
        <li>Fix a potential heap buffer overflow in FDT strlist parsing</li>
        <li>Fix a potential heap buffer overflow in Nordic HID peer validation</li>
        <li>Fix a potential OOB read in DFOTA modem response parsing</li>
        <li>Fix a potential path traversal vulnerability in firmware backup</li>
        <li>Fix a regression when searching for file magic</li>
        <li>Fix a regression when using report-export --sign</li>
        <li>Fix fwupd domain check bypass when using Qubes</li>
        <li>Ignore efivar free space requirement on Microsoft Hyper-V hosts</li>
        <li>Limit the number of hints a D-Bus client can set</li>
        <li>Limit the size of parsed USB descriptors to ~64KiB</li>
        <li>Make it easy to enable an authenticated remote</li>
        <li>Make the Novatek boot update more reliable</li>
        <li>Only read BCR from Intel SPI controllers</li>
        <li>Prevent a possible division by zero error in the progressbar code</li>
        <li>Prevent decompression bomb attacks in uSWID zlib payload parsing</li>
        <li>Prevent NVRAM-seeded ptential path traversal when loading ESP files</li>
        <li>Redact the username and password of remotes when using a non-active console</li>
        <li>Require authorization for firmware installation on emulated devices</li>
        <li>Require authorization for more D-Bus methods from non-local users</li>
        <li>Restrict Curl protocols to prevent potential SSRF attacks</li>
        <li>Restrict ModifyRemote to prevent a supply-chain redirection</li>
        <li>Show a short easy-to-read string as the Pixart touchpad name</li>
        <li>Tolerate post-quantum CA PKCS#7 failures when using Qubes</li>
        <li>Validate ACPI PHAT specific data offset before parsing</li>
        <li>Validate Corsair write size before subtracting header size</li>
        <li>Validate DFU address offset before parsing the header</li>
        <li>Validate Elan touchpad IAP address is within firmware bounds</li>
        <li>Validate Logitech TAP AP region bounds before calculating size</li>
        <li>Validate payload length is large enough for FPC sec-link</li>
        <li>Validate sector range before writing pixart-tp firmware</li>
        <li>Validate VBE area start does not exceed area size</li>
        <li>Validate write offset does not exceed TI TPS6598x stream size</li>
      </ul>
      
      <p>This release adds support for the following hardware:</p>
      
      <ul>
        <li>Egis MoC devices with PID 9201</li>
        <li>Intel Arc Pro B65 and Arc Pro B70 (#10389)</li>
        <li>Lenovo dock devices in 'provisioned' mode</li>
        <li>Pixart TP devices with PID 1343</li>
        <li>Several GigaDevice and Puya SPI chips</li>
      </ul>
ContentRating:
  oars-1.1:
    social-info: moderate