user256088011, Здравствуйте! Удалось ли вам решить проблему с постоянно всплывающим обновлением secure boot dbx? Если удалось, то как?
Пользователь добавил сообщение 29 Июня 2025, 20:18:48:
У меня ноутбук Dell vostro 3400. Ubuntu 20.04. Такая же проблема при обновлении secure boot dbx 466 -> 20241101,
sergey@sergey-Vostro-3400:~$ sudo fwupdmgr get-devices
[sudo] пароль для sergey:
Vostro 3400
│
├─CL1-3D512-Q11 NVMe SSSTC 512GB:
│ Device ID: 71b677ca0f1bc2c5b804fa1d59e52064ce589293
│ Summary: NVM Express solid state drive
│ Current version: 22321116
│ Vendor: Intel Corporation (NVME:0x1E95)
│ Serial Number: TW07YGY09DH0015P019Y
│ GUID: 2839f15a-f52e-524f-bd6c-2a90db8e0b3f ← STORAGE-DELL-108814
│ d8b197d0-0b03-4138-8ea6-8366a0cfde4a
│ Device Flags: • Internal device
│ • Updatable
│ • System requires external power source
│ • Supported on remote server
│ • Needs a reboot after installation
│ • Device is usable for the duration of the update
│ • Signed Payload
│
├─System Firmware:
│ │ Device ID: a45df35ac0e948ee180fe216a5f703f32dda163f
│ │ Summary: UEFI ESRT device
│ │ Current version: 1.38.0
│ │ Minimum Version: 1.38.0
│ │ Vendor: Dell (DMI:Dell Inc.)
│ │ Update State: Success
│ │ GUID: 5436e16d-4788-6c95-22d6-e5a0c1f9935a
│ │ 230c8b18-8d9b-53ec-838b-6cfc0383493a ← main-system-firmware
│ │ Device Flags: • Internal device
│ │ • Updatable
│ │ • System requires external power source
│ │ • Supported on remote server
│ │ • Needs a reboot after installation
│ │ • Cryptographic hash verification is available
│ │ • Device is usable for the duration of the update
│ │
│ └─UEFI dbx:
│ Device ID: 362301da643102b9f38477387e2193e57abaa590
│ Summary: UEFI revocation database
│ Current version: 466
│ Minimum Version: 466
│ Vendor: UEFI:Linux Foundation
│ Install Duration: 1 second
│ GUID: 00fe3755-a4d8-5ef7-ba5f-47979fbb3423 ← UEFI\CRT_E28D59CA489BD2AD580F2EA5D62D6A29BB9C02AE5A818434A37DA7FC11DFF9E9
│ 4a6cd2cb-8741-5257-9d1f-89a275dacca7 ← UEFI\CRT_E28D59CA489BD2AD580F2EA5D62D6A29BB9C02AE5A818434A37DA7FC11DFF9E9&ARCH_X64
│ c6682ade-b5ec-57c4-b687-676351208742 ← UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503
│ f8ba2887-9411-5c36-9cee-88995bb39731 ← UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64
│ Device Flags: • Internal device
│ • Updatable
│ • Supported on remote server
│ • Needs a reboot after installation
│ • Only version upgrades are allowed
│ • Signed Payload
│
├─TPM 2.0:
│ Device ID: a3487e128cf1413519bce8e9a1ab3f5981e61458
│ Summary: UEFI ESRT device
│ Current version: 7.2.2.0
│ Vendor: Dell Inc. (PCI:0x1028)
│ Update State: Success
│ Update Error: Updating disabled due to TPM ownership
│ GUID: 4572d2c1-a510-5d19-946a-227d0a0bd2ff ← 0a23-2.0
│ ff71992e-52f7-5eea-94ef-883e56e034c6 ← system-tpm
│ 7d65b10b-bb24-552d-ade5-590b3b278188 ← DELL-TPM-2.0-NTC-NPCT
│ 6f5ddd3a-8339-5b2a-b9a6-cf3b92f6c86d ← DELL-TPM-2.0-NTC-NPCT75x
│ decece50-de59-5e1b-b400-73229f7ddbf9 ← DELL-TPM-2.0-NTC-NPCT75x"!!4
│ d1ebc49b-e614-52eb-a8e1-44b562c94a2e ← DELL-TPM-2.0-NTC-NPCT75x"!!4rls
│ Device Flags: • Internal device
│ • System requires external power source
│
├─UEFI Device Firmware:
│ Device ID: 349bb341230b1a86e5effe7dfe4337e1590227bd
│ Summary: UEFI ESRT device
│ Current version: 188
│ Minimum Version: 188
│ Vendor: DMI:Dell Inc.
│ Update State: Success
│ GUID: 176e090d-0ddb-495e-8173-bc998ccfecd0
│ Device Flags: • Internal device
│ • Updatable
│ • System requires external power source
│ • Needs a reboot after installation
│ • Device is usable for the duration of the update
│
└─UEFI Device Firmware:
Device ID: 2292ae5236790b47884e37cf162dcf23bfcd1c60
Summary: UEFI ESRT device
Current version: 573706518
Minimum Version: 573706518
Vendor: Dell (DMI:Dell Inc.)
Update State: Success
GUID: d8b197d0-0b03-4138-8ea6-8366a0cfde4a
Device Flags: • Internal device
• Updatable
• System requires external power source
• Supported on remote server
• Needs a reboot after installation
• Device is usable for the duration of the update
________________________________________________
Devices that were not updated correctly:
• UEFI dbx (466 → 20241101)
Devices that have been updated successfully:
• System Firmware (1.37.0 → 1.38.0)
Uploading firmware reports helps hardware vendors to quickly identify failing and successful updates on real devices.
Upload report now? (Requires internet connection) [Y|n]:
n
Do you want to disable this feature for future updates? [y|N]:
n
Declined upload
sergey@sergey-Vostro-3400:~$ sudo fwupdmgr get-history
Vostro 3400
│
├─System Firmware:
│ │ Device ID: a45df35ac0e948ee180fe216a5f703f32dda163f
│ │ Previous version: 1.37.0
│ │ Update State: Success
│ │ Last modified: 2025-06-27 18:18
│ │ GUID: 5436e16d-4788-6c95-22d6-e5a0c1f9935a
│ │ Device Flags: • Internal device
│ │ • Updatable
│ │ • System requires external power source
│ │ • Supported on remote server
│ │ • Needs a reboot after installation
│ │ • Cryptographic hash verification is available
│ │ • Device is usable for the duration of the update
│ │
│ └─Vostro 3400, Inspiron 3501, Vostro 3500:
│ New version: 1.38.0
│ Remote ID: lvfs
│ Release ID: 111471
│ Summary: Firmware for the Dell Vostro 3400, Inspiron 3501, Vostro 3500
│ License: Proprietary
│ Size: 17,0 MB
│ Created: 2025-03-27
│ Urgency: Critical
│ Vendor: Dell
│ Description:
│ Fixes and Enhancements
│
│ ==========================
│
│ • This release contains security updates as disclosed in the Dell Security Advisories.
│
└─UEFI dbx:
│ Device ID: 362301da643102b9f38477387e2193e57abaa590
│ Previous version: 466
│ Update State: Failed
│ Update Error: failed to run update on reboot
│ Last modified: 2025-06-29 16:49
│ GUID: 00fe3755-a4d8-5ef7-ba5f-47979fbb3423
│ Device Flags: • Internal device
│ • Updatable
│ • Supported on remote server
│ • Needs a reboot after installation
│
└─Secure Boot dbx:
New version: 20241101
Remote ID: lvfs
Release ID: 108324
Summary: UEFI Secure Boot Forbidden Signature Database
Variant: x64-compat
License: Proprietary
Size: 23,3 kB
Created: 2023-05-09
Urgency: High
Vendor: Linux Foundation
Duration: 1 second
Release Flags: • Is upgrade
Description:
This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.
An insecure version of Howyar's SysReturn software was added, due to a security vulnerability that allowed an attacker to bypass UEFI Secure Boot.
sergey@sergey-Vostro-3400:~$ sudo fwupdmgr refresh --force && sudo fwupdmgr update --force
Updating lvfs
Downloading… [***************************************]
Downloading… [***************************************]
Successfully downloaded new metadata: 4 local devices supported
Devices with no available firmware updates:
• UEFI Device Firmware
Devices with the latest available firmware version:
• CL1-3D512-Q11 NVMe SSSTC 512GB
• System Firmware
• UEFI Device Firmware
╔══════════════════════════════════════════════════════════════════════════════╗
║ Upgrade UEFI dbx from 466 to 20241101? ║
╠══════════════════════════════════════════════════════════════════════════════╣
║ This updates the list of forbidden signatures (the "dbx") to the latest ║
║ release from Microsoft. ║
║ ║
║ An insecure version of Howyar's SysReturn software was added, due to a ║
║ security vulnerability that allowed an attacker to bypass UEFI Secure Boot. ║
║ ║
║ UEFI dbx and all connected devices may not be usable while updating. ║
╚══════════════════════════════════════════════════════════════════════════════╝
Perform operation? [Y|n]: y
Downloading… [***************************************]
Распаковка… [***************************************]
Распаковка… [***************************************]
Authenticating… [***************************************]
Authenticating… [***************************************]
Перезапуск устройства… [***************************************]
Запись… [***************************************]
Распаковка… [***************************************]
Запись… [***************************************]
Перезапуск устройства… [***************************************]
Waiting… [***************************************]
Successfully installed firmware
An update requires a reboot to complete. Restart now? [y|N]: y
sergey@sergey-Vostro-3400:~$
sergey@sergey-Vostro-3400:~$ fwupdmgr --version
runtime org.freedesktop.fwupd 1.7.9
runtime com.dell.libsmbios 2.4
compile org.freedesktop.gusb 0.3.4
runtime org.kernel 5.15.0-142-generic
compile com.hughsie.libjcat 0.1.4
compile org.freedesktop.fwupd 1.7.9
runtime org.freedesktop.gusb 0.3.4
sergey@sergey-Vostro-3400:~$
Обновление через терминал вроде выполняется и пишет что текущая версия 466, но после перезагрузки опять появляется в Ubuntu software. И в истории пишет failed to run update on reboot.
Devices that were not updated correctly:
• UEFI dbx (466 → 20241101)
Devices that have been updated successfully:
• System Firmware (1.37.0 → 1.38.0)
До этого нормально установилось secure boot dbx 77 -> 20241101.
Сбрасывал ключи в BIOS. После этого опять прилетает обновление secure boot dbx 77 -> 20241101 и нормально устанавливается. Тут же появляется secure boot dbx 466 -> 20241101 и с ним уже проблемы...
Подскажите пожалуйста куда копать?