Fwupd 2.1.8 Ships with RSA-3072 Verification and Memory-Safety Fixes
Fwupd 2.1.8, the open-source Linux firmware-update daemon, released on 24 September 2026 with new cryptographic checks and more than twenty bug fixes. Its two headline features are a plugin that syncs bootupd when the EFI System Partition changes, and RSA-3072 signature verification for Lenovo accessories. Most of the release closes memory-safety holes attackers love, including a Synaptics buffer overwrite, a FocalTech integer underflow, and an LZMA decompression cap. Users on Fedora, Ubuntu, Debian, RHEL and other distros get the fixes automatically through their normal update flow, or via the fwupdmgr command line.
Fwupd 2.1.8 Ships with RSA-3072 Verification and Memory-Safety Fixes @ Linux Compatible
Fwupd 2.1.8 Ships with RSA-3072 Verification and Memory-Safety Fixes
Fwupd 2.1.8, released on September 24, 2026, introduces new cryptographic checks and over twenty bug fixes focused on improving memory safety and security in Linux firmware updates. Key features include a plugin for synchronizing bootupd with changes to the EFI System Partition and RSA-3072 signature verification for Lenovo accessories, enhancing protection against potential vulnerabilities. The release addresses critical memory-safety issues, such as buffer overflows and integer underflows, which could lead to severe security risks like remote code execution. Users across various Linux distributions can automatically receive these updates, ensuring a more secure and reliable firmware update process without the need for complex manual interventions
