⇦ | fwupd [community]
Last updated on: 2026-08-01 02:03 [UTC]

Metadata for fwupd in community

org.freedesktop.fwupd - 2.1.7-r0 ⚙ aarch64 ⚙ armhf ⚙ armv7 ⚙ x86 ⚙ x86_64

Icon
<component type="console-application">
  <id>org.freedesktop.fwupd</id>
  <name>fwupd</name>
  <summary>Update device firmware on Linux</summary>
  <project_license>LGPL-2.0+</project_license>
  <developer_name>The fwupd authors</developer_name>
  <description>
    <p>
      This project aims to make updating firmware on Linux automatic, safe and
      reliable.
      You can either use a GUI software manager like GNOME Software to view and
      apply updates, the command-line tool or the D-Bus interface directly.
    </p>
    <p>
      The fwupd process is a system daemon to allow session software to update
      device firmware on your local machine.
      It is designed for desktops, but this project is also usable on phones,
      tablets and on headless servers.
    </p>
  </description>
  <pkgname>fwupd</pkgname>
  <url type="homepage">https://fwupd.org/</url>
  <url type="bugtracker">https://github.com/fwupd/fwupd/issues</url>
  <url type="translate">https://hosted.weblate.org/projects/fwupd/fwupd/</url>
  <url type="vcs-browser">https://github.com/fwupd/fwupd</url>
  <provides>
    <binary>fwupdmgr</binary>
    <binary>fwupdtool</binary>
  </provides>
  <languages>
    <lang percentage="97">ar</lang>
    <lang percentage="86">bg</lang>
    <lang percentage="89">ca</lang>
    <lang percentage="100">cs</lang>
    <lang percentage="49">da</lang>
    <lang percentage="100">de</lang>
    <lang percentage="100">en_GB</lang>
    <lang percentage="100">en_US</lang>
    <lang percentage="100">es</lang>
    <lang percentage="58">et</lang>
    <lang percentage="98">fi</lang>
    <lang percentage="35">fr</lang>
    <lang percentage="45">fur</lang>
    <lang percentage="43">he</lang>
    <lang percentage="80">hi</lang>
    <lang percentage="85">hr</lang>
    <lang percentage="76">hu</lang>
    <lang percentage="100">id</lang>
    <lang percentage="69">it</lang>
    <lang percentage="93">ja</lang>
    <lang percentage="36">ka</lang>
    <lang percentage="93">kk</lang>
    <lang percentage="77">ko</lang>
    <lang percentage="43">lt</lang>
    <lang percentage="41">nl</lang>
    <lang percentage="100">pl</lang>
    <lang percentage="100">pt</lang>
    <lang percentage="100">pt_BR</lang>
    <lang percentage="100">ro</lang>
    <lang percentage="100">ru</lang>
    <lang percentage="55">si</lang>
    <lang percentage="100">sl</lang>
    <lang percentage="93">sq</lang>
    <lang percentage="93">sr</lang>
    <lang percentage="100">sv</lang>
    <lang percentage="48">tr</lang>
    <lang percentage="98">uk</lang>
    <lang percentage="99">zh_CN</lang>
    <lang percentage="58">zh_TW</lang>
  </languages>
  <releases>
    <release type="stable" version="2.1.7" timestamp="1785110400">
      <description>
        <p>
          This release adds the following features:
        </p>
        <ul>
          <li>Add "well known" AppStream IDs for common BIOS settings</li>
          <li>Add MTD lock security attribute</li>
          <li>Add support for "externally managed" EFI signature lists</li>
          <li>Add systemd-pcrlock plugin and hook up to UEFI updates</li>
          <li>Add TCG disk encryption security attribute</li>
          <li>Enable more plugins when compiling for Android</li>
        </ul>
        <p>This release fixes the following bugs:</p>
        <ul>
          <li>Add wrappers for input streams for future Rust implementations</li>
          <li>Allow overriding some methods in FwupdClient for a future refactor</li>
          <li>Allow plain string versions for some AMD GPUs</li>
          <li>Allow suspend-to-ram with encrypted RAM</li>
          <li>Always test Dell dock type when connected</li>
          <li>Avoid possible out-of-bounds read in when parsing the DFU sector</li>
          <li>Do not abort when udisks cannot resolve a device</li>
          <li>Do not allow force installs over D-Bus</li>
          <li>Do not fail to start when a pre-group comment has no keys set</li>
          <li>Fall back to copying the file descriptor contents when not sealed</li>
          <li>Fix dropped status updates during updates</li>
          <li>Fix FW update for Lenovo TBT5 Smart Dock 7500</li>
          <li>Fix fwupd-refresh.service polkit auth errors</li>
          <li>Fix segfault parsing some logitech-hidpp bootloader records</li>
          <li>Fix the seal self tests when building on a tmpfs</li>
          <li>Fix update failure when the TP IC is in bootloader-only mode</li>
          <li>Mark Coreboot VBOOT as obsoleting BootGuard verified</li>
          <li>Move more per-class limits to the class instances to reduce RSS</li>
          <li>Prepare modem-manager firmware after firehose detach</li>
          <li>Reject out-of-range CCGX device mode before indexing versions</li>
          <li>Require trusted metadata for device updates</li>
          <li>Require trusted metadata when using OnlyTrusted</li>
          <li>Skip modem-manager secboot status when unsupported</li>
          <li>Use safe reads for synaptics-rmi device responses</li>
          <li>Validate GUID-defined section offset against EFI section size</li>
        </ul>
        <p>This release adds support for the following hardware:</p>
        <ul>
          <li>PixArt PJP360 device</li>
        </ul>
      </description>
    </release>
    <release type="stable" version="2.1.6" timestamp="1782864000">
      <description>
        <p>
          This release adds the following features:
        </p>
        <ul>
          <li>Add --filter-protocol to fwupdmgr and fwupdtool</li>
          <li>Add a new HSI attribute for coreboot verified boot</li>
          <li>Add hashes for the latest DBX for offline machines</li>
          <li>Allow parsing Hayden Bridge Thunderbolt firmware</li>
          <li>Handle HPE Redfish reset-required updates</li>
          <li>Ignore efivar free space on VMWare, GCE and EC2 VMs</li>
          <li>Prevent FwupdClient from downloading the same file multiple times</li>
          <li>Split UEFI Memory Protection HSI from NX Compat</li>
        </ul>
        <p>This release fixes the following bugs:</p>
        <ul>
          <li>Avoid an integer overflow in the ifwi-cpd manifest length check</li>
          <li>Avoid truncating the AMD Kria FRU board area offset</li>
          <li>Block dbx updates on ASUSTeK GL553VD</li>
          <li>Check SMEE hardware bit directly for AMD SME detection</li>
          <li>Create the ESP OS directory if not found</li>
          <li>Detect the BCR device on Celeron LPC SPI controllers</li>
          <li>Fall back to a binary firmware when no specific MTD image type is set</li>
          <li>Fix AI table clear behavior of the elantp boot code.</li>
          <li>Fix errors with fwupd-refresh service not working properly</li>
          <li>Fix Genesys GL32xx device locker crash due to argument mismatch</li>
          <li>Fix installing KEK updates when using snapd by sending the correct blob</li>
          <li>Fix integer underflow when Elan firmware is smaller than one page</li>
          <li>Fix possible NULL pointer dereference when updating SteelSeries firmware</li>
          <li>Fix the display of the HP UEFI db certificate</li>
          <li>Improved usi-dock progress reporting behavior</li>
          <li>Increase the parser item limit from 100 to 1000 for large KEKs</li>
          <li>Log out of the Redfish session when required on HPE hardware</li>
          <li>Only show 'authenticating' after a short delay</li>
          <li>Re-process the device metadata when required after all devices are added</li>
          <li>Require sealed memfd input to prevent possible TOCTOU attacks</li>
          <li>Sanitize the Jabra GNP device version in a more secure way</li>
          <li>Validate raydium-tp buffer size before direct index access</li>
          <li>Validate that Lenovo dock device-reported program sizes are valid</li>
        </ul>
        <p>This release adds support for the following hardware:</p>
        <ul>
          <li>Lenovo dual-bank accessory dongle and paired peripherals</li>
        </ul>
      </description>
    </release>
    <release type="stable" version="2.1.5" timestamp="1780963200">
      <description>
        <p>
          This release adds the following features:
        </p>
        <ul>
          <li>Allow overriding the detected CPU vendor to allow more self tests</li>
          <li>Allow updating the Windows-specific UEFI CA on dual boot machines</li>
          <li>Install the db updates on broken hardware with new firmware</li>
        </ul>
        <p>This release fixes the following bugs:</p>
        <ul>
          <li>Add tests for the vbe, upower, uefi-sbat, pci-bcr, mtd, gpio and msr plugins</li>
          <li>Check the array index in some runtime-generated code</li>
          <li>Claim the udev netlink backend before old libusb versions</li>
          <li>Expand the netlink socket buffer to prevent packet loss during event floods</li>
          <li>Fix a msgpack regression when updating some Huddly cameras</li>
          <li>Fix HID feature read buffer size in goodix-tp device probe</li>
          <li>Fix reproducible builds</li>
          <li>Fix the check-reboot-needed command</li>
          <li>Increase the i2c-hid re-bind delay for synaptics-rmi PID 0x96e7</li>
          <li>Parse the dell-dock marketing name in a more safe way</li>
          <li>Set a firmware size limit on intel-gsc aux and oprom firmware types</li>
          <li>Simplify the engine by only loading the config object once</li>
          <li>Use a cryptographically secure RNG when building the idle and inhibit IDs</li>
          <li>Use a more appropriate firmware maximum size for Huddly cameras</li>
        </ul>
        <p>This release adds support for the following hardware:</p>
        <ul>
          <li>Elan touchscreens</li>
        </ul>
      </description>
    </release>
    <release type="stable" version="2.1.4" timestamp="1780012800">
      <description>
        <p>
          This release adds the following features:
        </p>
        <ul>
          <li>Add a libcrypto-based JCat implementation for Android</li>
          <li>Add support for NixOS to the quickstart script</li>
          <li>Add support for the Compal BIOS version format</li>
          <li>Allow a remote to specify that a username or password is required</li>
          <li>Allow storing a per-user password in XDG_CONFIG_HOME</li>
          <li>Detect encrypted swap devices below device-mapper</li>
          <li>Ensure that all firmware subclasses set the maximum size</li>
          <li>Remove the flashrom plugin</li>
          <li>Save the SMBIOS BiosReleaseDate string to uploaded reports</li>
          <li>Tell Star Labs coreboot users to manually update when required</li>
        </ul>
        <p>This release fixes the following bugs:</p>
        <ul>
          <li>Add a retry limit when updating failing Goodix MoC devices</li>
          <li>Add several bounds checks for when updating Dell docks</li>
          <li>Add vendor name and name for the various Framework UEFI certificates</li>
          <li>Allow recovery if the Lenovo dock internal state is invalid</li>
          <li>Avoid trunctaion when calculating the AMD GPU atombios size</li>
          <li>Check firmware size against Novatek flash start address</li>
          <li>Check for config offset overflow when updating Synaptics RMI devices</li>
          <li>Check for multiplication overflow in BCM57xx stage1 size calculation</li>
          <li>Check for overflow when writing to CCGX DMC devices</li>
          <li>Check stream size before calculating Legion HID ID offset</li>
          <li>Check stream size before subtracting Ilitek ITS CRC length</li>
          <li>Clear Sunplus camera download state if the previous flash failed</li>
          <li>Do not show plugin warnings when using --version</li>
          <li>Filter the install flags provided by the D-Bus client</li>
          <li>Fix a potential heap buffer overflow in FDT strlist parsing</li>
          <li>Fix a potential heap buffer overflow in Nordic HID peer validation</li>
          <li>Fix a potential OOB read in DFOTA modem response parsing</li>
          <li>Fix a potential path traversal vulnerability in firmware backup</li>
          <li>Fix a regression when searching for file magic</li>
          <li>Fix a regression when using report-export --sign</li>
          <li>Fix fwupd domain check bypass when using Qubes</li>
          <li>Ignore efivar free space requirement on Microsoft Hyper-V hosts</li>
          <li>Limit the number of hints a D-Bus client can set</li>
          <li>Limit the size of parsed USB descriptors to ~64KiB</li>
          <li>Make it easy to enable an authenticated remote</li>
          <li>Make the Novatek boot update more reliable</li>
          <li>Only read BCR from Intel SPI controllers</li>
          <li>Prevent a possible division by zero error in the progressbar code</li>
          <li>Prevent decompression bomb attacks in uSWID zlib payload parsing</li>
          <li>Prevent NVRAM-seeded ptential path traversal when loading ESP files</li>
          <li>Redact the username and password of remotes when using a non-active console</li>
          <li>Require authorization for firmware installation on emulated devices</li>
          <li>Require authorization for more D-Bus methods from non-local users</li>
          <li>Restrict Curl protocols to prevent potential SSRF attacks</li>
          <li>Restrict ModifyRemote to prevent a supply-chain redirection</li>
          <li>Show a short easy-to-read string as the Pixart touchpad name</li>
          <li>Tolerate post-quantum CA PKCS#7 failures when using Qubes</li>
          <li>Validate ACPI PHAT specific data offset before parsing</li>
          <li>Validate Corsair write size before subtracting header size</li>
          <li>Validate DFU address offset before parsing the header</li>
          <li>Validate Elan touchpad IAP address is within firmware bounds</li>
          <li>Validate Logitech TAP AP region bounds before calculating size</li>
          <li>Validate payload length is large enough for FPC sec-link</li>
          <li>Validate sector range before writing pixart-tp firmware</li>
          <li>Validate VBE area start does not exceed area size</li>
          <li>Validate write offset does not exceed TI TPS6598x stream size</li>
        </ul>
        <p>This release adds support for the following hardware:</p>
        <ul>
          <li>Egis MoC devices with PID 9201</li>
          <li>Intel Arc Pro B65 and Arc Pro B70 (#10389)</li>
          <li>Lenovo dock devices in 'provisioned' mode</li>
          <li>Pixart TP devices with PID 1343</li>
          <li>Several GigaDevice and Puya SPI chips</li>
        </ul>
      </description>
    </release>
  </releases>
  <content_rating type="oars-1.1">
    <content_attribute id="social-info">moderate</content_attribute>
  </content_rating>
</component>