fwupd is the standard firmware update service on Linux. It checks the Linux Vendor Firmware Service (LVFS), where hardware vendors publish signed firmware, and installs updates for system firmware (UEFI/BIOS), NVMe and SATA drives, Thunderbolt controllers, docks and many other devices. In this tutorial you will use fwupdmgr on Ubuntu 24.04 to see which devices fwupd supports, check for and install updates, apply a UEFI capsule update, review the update history and roll back a device when necessary.

Prerequisites

To follow this guide you need:

  • A bare metal server or physical machine running Ubuntu 24.04 LTS. Virtual machines and VPS have no firmware you can update from inside the guest.
  • A non-root user with sudo privileges.
  • For system firmware (BIOS/UEFI) updates: a machine that boots in UEFI mode, with the EFI System Partition mounted at /boot/efi.
  • Outbound HTTPS access to fwupd.org and cdn.fwupd.org.
  • A current backup and a maintenance window. A firmware update usually needs a reboot, and a failed one can leave a device unusable.

Step 1 - Installing and checking fwupd

fwupd is installed by default on Ubuntu Desktop and on most Ubuntu Server images. Make sure it is present and up to date:

sudo apt update
sudo apt install fwupd

The fwupd daemon is started on demand by D-Bus when you run fwupdmgr, so you do not need to enable it. Check the versions:

fwupdmgr --version
compile   org.freedesktop.fwupd       1.9.x
runtime   org.freedesktop.fwupd       1.9.x
...

If you plan to update system firmware, confirm the machine booted in UEFI mode and that the EFI System Partition is mounted:

ls /sys/firmware/efi > /dev/null && echo "UEFI boot"
findmnt /boot/efi
UEFI boot
TARGET    SOURCE    FSTYPE OPTIONS
/boot/efi /dev/sda1 vfat   rw,relatime,fmask=0077,dmask=0077,...

Step 2 - Listing the devices fwupd can manage

Ask fwupd which devices it recognizes:

fwupdmgr get-devices

The output is a tree of devices. A shortened example:

Example Server

System Firmware:
    Device ID:          a45df35ac0e948ee180fe216a5f703f32dda163f
    Current version:    1.13.2
    Vendor:             Example Vendor (DMI:Example Vendor)
    Update State:       Success
    Device Flags:       • Internal device
                        • Updatable
                        • Needs a reboot after installation

UEFI dbx:
    Device ID:          362301da643102b9f38477387e2193e57abaa590
    Current version:    371
    Device Flags:       • Internal device
                        • Updatable

SAMSUNG MZQL2960HCJR-00A07:
    Device ID:          71b677ca0f1bc2c5b804fa1d59e52064ce589293
    Current version:    GDC5602Q
    Vendor:             Samsung Electronics Co Ltd (NVME:0x144D)
    Device Flags:       • Internal device
                        • Updatable

Devices without the Updatable flag are detected but cannot be updated through fwupd. Note the Device ID of any device you want to target individually.

The UEFI dbx entry is the Secure Boot revocation list. Updating it blocks bootloaders with known vulnerabilities, and it is one of the most common updates you will see on servers.

Step 3 - Checking for available updates

Download the latest firmware metadata from LVFS:

sudo fwupdmgr refresh
Updating lvfs
Downloading…             [***************************************]
Successfully downloaded new metadata: 1 local device supported

The first time, fwupd may ask you to agree to upload anonymous success reports to LVFS. Vendors use these reports to decide when an update is safe to publish widely. You can answer either way.

Ubuntu also enables the fwupd-refresh.timer, which refreshes the metadata automatically. Check it:

systemctl list-timers fwupd-refresh.timer

Now list the updates available for your devices:

fwupdmgr get-updates
Example Server

System Firmware:
    Device ID:          a45df35ac0e948ee180fe216a5f703f32dda163f
    Current version:    1.13.2
  
  Example Server System Firmware:
        New version:      1.14.1
        Remote ID:        lvfs
        Release ID:       98765
        Summary:          System firmware for the example server
        Urgency:          High
        Description:      This release contains security fixes ...

Read the description and urgency before installing anything. If fwupd reports No updatable devices or that there are no updates, your firmware is current or your hardware is not covered by LVFS.

Step 4 - Installing updates

To install every available update, run:

sudo fwupdmgr update

fwupd shows each update and asks for confirmation before downloading and installing it. For a controlled rollout on a server, update one device at a time by passing its Device ID:

sudo fwupdmgr update 71b677ca0f1bc2c5b804fa1d59e52064ce589293

Many devices, such as NVMe drives, are flashed immediately while the system runs:

Downloading…             [***************************************]
Decompressing…           [***************************************]
Writing…                 [***************************************]
Successfully installed firmware

Some of them still need a reboot to activate the new firmware. fwupdmgr asks if you want to restart now; if you answer no, schedule the reboot in your maintenance window.

UEFI and BIOS updates

System firmware cannot be rewritten while the OS runs. For these devices fwupd uses UEFI capsule updates:

  1. fwupdmgr downloads and verifies the capsule and stores it on the EFI System Partition.
  2. It sets a UEFI variable so the next boot starts fwupd's small EFI helper instead of Ubuntu.
  3. On reboot the helper hands the capsule to the firmware, which flashes itself. The screen may show a progress bar, and the server may restart more than once.
  4. The machine boots back into Ubuntu, and fwupd records whether the update succeeded.

Install the system firmware update and reboot when asked:

sudo fwupdmgr update a45df35ac0e948ee180fe216a5f703f32dda163f
sudo reboot

After the server is back, confirm the new version:

fwupdmgr get-devices

The System Firmware entry should now show the new version in its Current version field.

Step 5 - Reviewing the update history

fwupd keeps a record of every update it installed and its result:

fwupdmgr get-history
Example Server

System Firmware:
    Device ID:          a45df35ac0e948ee180fe216a5f703f32dda163f
    Previous version:   1.13.2
    Update State:       Success
  
  Example Server System Firmware:
        New version:      1.14.1

An Update State of Failed includes an error message explaining what went wrong. If the history still shows an update as pending after a reboot, the capsule was not applied; see Troubleshooting.

Step 6 - Rolling back a firmware update

If a new firmware version causes problems, you can install an older version of the same device, when the vendor allows it and LVFS still offers it:

sudo fwupdmgr downgrade 71b677ca0f1bc2c5b804fa1d59e52064ce589293

fwupdmgr lists the older versions available and lets you choose one. Many system firmware images block downgrades for security reasons, so a BIOS rollback may be refused; in that case follow your vendor's recovery procedure (often through the BMC).

Step 7 - Installing firmware on a server without internet access

For servers that cannot reach LVFS, download the firmware file (a .cab archive) on another machine from https://fwupd.org/lvfs/devices/ or from the vendor, copy it to the server, and install it locally:

scp firmware.cab your_user@your_server_ip:/tmp/

On the server:

sudo fwupdmgr install /tmp/firmware.cab

The .cab file contains the vendor's signature, and fwupd still verifies it before flashing. Only add --allow-older or --allow-reinstall when you deliberately want to install an older or identical version.

Troubleshooting

fwupdmgr get-devices does not list a device. fwupd only shows devices that one of its plugins supports. Check which plugins are active and why others are disabled with fwupdmgr get-plugins, and look for errors with sudo journalctl -u fwupd -n 100.

A UEFI update stays pending after reboot. The firmware did not run the capsule. Check that Secure Boot allows fwupd's signed EFI helper, that the EFI System Partition has free space (df -h /boot/efi), and that the machine really booted in UEFI mode. The error is recorded in fwupdmgr get-history.

Signature or certificate errors when refreshing. A wrong system clock breaks certificate validation. Check timedatectl, fix the time, and run sudo fwupdmgr refresh --force.

fwupdmgr update says the device requires AC power or a battery level. fwupd refuses to flash laptops on battery. Connect the power adapter and try again.

Conclusion

You checked which devices on your machine fwupd supports, refreshed LVFS metadata, installed device and UEFI capsule updates, verified the result in the update history and learned how to roll back or update offline. As next steps, add fwupdmgr get-updates to your regular maintenance checklist, test each firmware release on one server before rolling it out to the rest, and review the security posture of your hardware with fwupdmgr security.