Skip to content

Framework Desktop — BIOS & Drivers

Subscribe to release notifications to get an email when new BIOS or driver updates are published for your Framework Desktop.

You can check your current BIOS version before installing an update.


3.06
Released 2026-08-03·20.4 MB
Stable
Latest
Installation
Downloads
FileRelease Date
Windows BIOS v3.06 Installer2026-08-03Framework_Desktop_Ryzen_AI_MAX_300_BIOS_3.06.exeSHA256 · 1D91EDB92766D9252AC0E185C94729B5234935FFA21056DFCCDE9592BCD817C1
EFI Shell Update (BIOS v3.06)2026-08-03Framework_Desktop_Ryzen_AI_MAX_300_BIOS_3.06_EFI.zipSHA256 · 68C251BF20B98C9D0928DDAD51DD920A3B073AA4E1C8BE55FF43454B8B38C013
Highlights
  • Update AMD PI to 1.0.0.2c.
  • Modified the F2 key in the F12 Boot Menu to go to the setup menu instead of the settings menu to allow easier navigation to secure boot settings.
  • Added support for the single-ROM BIOS Crisis Recovery feature.
  • Implemented a delay in sending the 3A profile to prevent incomplete UCSI PPM command resets during S0 boot transitions.
  • Added validation logic to reject invalid USB PD index values.
  • Fixed a boot hang issue occurring with specific video encoder cards.
  • Resolved an issue where an unidentified UART device appeared in the BIOS, and fixed a bug causing console support to be lost following a BIOS update.
  • Fixed an issue where the system was unable to boot from partially locked self-encrypting drives (SEDs)
  • Resolved an issue where the iGPU memory size was incorrectly capped at 24 GB on systems populated with 96 GB of system memory.
  • Security Fix: CVE-2026-6726 (CVSS Score 7.9) - An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.
  • Security Fix: CVE-2025-62626 (CVSS Score 7.2) - Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
  • Security Fix: CVE-2025-54502 (CVSS Score 7.1) - Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.
  • Security Fix: CVE-2026-6727 (CVSS Score 5.9) - A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.
  • Security Fix: CVE-2024-36345 (CVSS Score 4.6) - Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality.
  • Security Fix: CVE-2024-36343 (CVSS Score N/A) - libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
View all BIOS v3.06 details
FileRelease Date
Windows Driver Bundle v1.042026-08-17Framework_Desktop_AMD_Ryzen_AI_Max_300_driver_bundle_W11_v104_2026_08_03.exeSHA256 · 2B2249316C637F75D000CA41B71CB547B5A1BA9115E5815C05A39260BD728108
Wi-Fi Driver for use during Windows Installation2026-09-03Framework_W11_OOBE_Wifi_Driver_Package.zipSHA256 · BD427CC233BAAA7CC8522823603390A50FA425BC302D2192CB7900017B5BD044