Skip to content

efivars out of space - framework desktop #237

Description

@paragm

Device Information

System Model or SKU

AMD Ryzen AI Max 395

Please select one of the following

  • Framework Desktop (AMD Ryzen™ AI 300 PRO Series)

BIOS VERSION

03.05

Describe the bug

A clear and concise description of what the bug is.

Steps To Reproduce

Steps to reproduce the behavior:

$ fwupdmgr refresh --force && fwupdmgr get-updates && fwupdmgr update
Updating lvfs
Downloading…             [ -                                     ]
Successfully downloaded new metadata:
 • 4 devices are updatable
 • 3 devices are supported in the enabled remotes (an update has been published)
Devices with no available firmware updates:
 • KEK CA
 • Option ROM UEFI CA
 • Windows UEFI CA
 • frame.work-LaptopDB
 • frame.work-LaptopKEK
 • Hub
 • WD BLACK SN7100 1TB
 • WD BLACK SN7100 1TB
Devices with the latest available firmware version:
 • UEFI CA
 • System Firmware
Framework Desktop (AMD Ryzen AI Max 300 Series)
│
└─UEFI dbx:
  │   Device ID:          362301da643102b9f38477387e2193e57abaa590
  │   Summary:            UEFI revocation database
  │   Current version:    20250507
  │   Minimum Version:    20250507
  │   Vendor:             Microsoft (UEFI:Microsoft)
  │   Install Duration:   1 second
  │   Update Error:       Not enough efivarfs space, requested 30.7 kB and got 1.6 kB
  │   GUIDs:              f8ba2887-9411-5c36-9cee-88995bb39731 ← UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64
  │                       d07ff664-b0e1-5f4e-a723-d7fbcbfcb94f ← UEFI\CRT_3CD3F0309EDAE228767A976DD40D9F4AFFC4FBD5218F2E8CC3C9DD97E8AC6F9D&ARCH_X64
  │                       69b2c147-9eaf-5793-a6fc-3d152320013c ← UEFI\CRT_80A010B8D42DDC03614704B050BBF9A43D3084CD0583D7829E7AE4F797DE6628&ARCH_X64
  │   Device Flags:       • Internal device
  │                       • Supported on remote server
  │                       • Needs a reboot after installation
  │                       • Device is usable for the duration of the update
  │                       • Updatable
  │                       • Only version upgrades are allowed
  │                       • Signed Payload
  │                       • Can tag for emulation
  │
  ├─Secure Boot dbx Configuration Update:
  │     New version:      20260402
  │     Remote ID:        lvfs
  │     Release ID:       143971
  │     Summary:          UEFI Secure Boot Forbidden Signature Database
  │     Variant:          x64
  │     License:          Proprietary
  │     Size:             24.6 kB
  │     Created:          2025-09-02 00:00:00
  │     Urgency:          High
  │       Tested:         2026-07-20 00:00:00
  │       Distribution:   rhel 10.0
  │       Old version:    20160809
  │       Version[fwupd]: 2.0.19
  │     Vendor:           Linux Foundation
  │     Duration:         1 second
  │     Release Flags:    • Trusted metadata
  │                       • Is upgrade
  │     Description:
  │     This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.
  │
  │     Some insecure bootloaders were added, due to security vulnerabilities that allowed an attacker to bypass UEFI Secure Boot. The additional entries were from:
  │
  │     • Baramanudi Management Suite
  │     • EAZ EasyFix
  │     • Finland Matriculation Examination Board
  │     • NTC IT ROSA Linux
  │     • PC-Doctor
  │     • Spyrus WTGCreator
  │     • WhiteCanyon blancco
  │     • Some ancient shim releases for OpenSUSE, Oracle and Red Hat
  │     Issues:           616257
  │                       CVE-2026-8863
  │     Checksum:         9edea8bc287bf9bf4659856b28cf421f330eb2f658c163eab0a03512a98c0e78
  │
  └─Secure Boot dbx Configuration Update:
        New version:      20250902
        Remote ID:        lvfs
        Release ID:       130035
        Summary:          UEFI Secure Boot Forbidden Signature Database
        Variant:          x64
        License:          Proprietary
        Size:             24.1 kB
        Created:          2025-09-02 00:00:00
        Urgency:          High
          Tested:         2026-07-06 00:00:00
          Distribution:   debian 13
          Old version:    20250507
          Version[fwupd]: 2.0.20
          Tested:         2026-06-08 00:00:00
          Distribution:   ubuntu 26.04
          Old version:    20230501
          Version[fwupd]: 2.1.1
          Tested:         2026-04-20 00:00:00
          Distribution:   ubuntu 25.10
          Old version:    20230501
          Version[fwupd]: 2.0.16
          Tested:         2026-02-25 00:00:00
          Distribution:   ubuntu 25.10
          Old version:    20230501
          Version[fwupd]: 2.0.18
          Tested:         2026-02-13 00:00:00
          Distribution:   ubuntu 25.10
          Old version:    20230501
          Version[fwupd]: 2.0.17
          Tested:         2025-12-05 00:00:00
          Distribution:   fedora 42 (workstation)
          Old version:    20250507
          Version[fwupd]: 2.0.17
          Tested:         2025-11-10 00:00:00
          Distribution:   fedora 43 (kde)
          Old version:    20230501
          Version[fwupd]: 2.0.16
        Vendor:           Linux Foundation
        Duration:         1 second
        Release Flags:    • Trusted metadata
                          • Is upgrade
                          • Tested by trusted vendor
        Description:
        This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.

        Some insecure versions of the IGEL bootloader were added, due to a security vulnerability that allowed an attacker to bypass UEFI Secure Boot.
        Issue:            CVE-2025-47827
        Checksum:         7178302fa23fcb875e7540900e299fb30a76758663efb7e1c56edc25cd3f316a

UEFI dbx is not currently updatable:
 • Not enough efivarfs space, requested 30.7 kB and got 1.6 kB
Devices with the latest available firmware version:
 • UEFI CA
 • System Firmware
Devices with no available firmware updates:
 • KEK CA
 • Option ROM UEFI CA
 • Windows UEFI CA
 • frame.work-LaptopDB
 • frame.work-LaptopKEK
 • Hub
 • WD BLACK SN7100 1TB
 • WD BLACK SN7100 1TB

Operating System (please complete the following information):

Linux [hostname] 7.0.0-27-generic #27-Ubuntu SMP PREEMPT_DYNAMIC Thu Jun 18 19:13:49 UTC 2026 x86_64 GNU/Linux

Issue Description

Similar to #90, #235 , running fwupdmgr refresh --force && fwupdmgr get-updates && fwupdmgr update gives the error Not enough efivarfs space, requested 30.7 kB and got 1.6 kB

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions