Framework Laptop 13 11th Gen Intel® Core™ — BIOS 3.22
Downloads
Section titled “Downloads”- After updating to 3.22, you will not be able to downgrade to an earlier version
- Security fix: CVE-2023-38655 — Improper buffer restrictions in firmware (CVSS 6.8)
- Security fix: CVE-2022-35897 — Stack buffer overflow vulnerability leading to arbitrary code execution (CVSS 6.8)
- Security fix: CVE-2024-49200 — AcpiS3SaveDxe and ChipsetSvcDxe vulnerability (CVSS 6.4)
- Security fix: CVE-2024-30211 — Improper access control in Intel ME driver pack installer (CVSS 6.0)
- Security fix: CVE-2023-40067 — Unchecked return value in firmware (CVSS 5.7)
- Security fix: CVE-2024-28956 — Enhancement to address security vulnerability (CVSS 5.6)
- Security fix: CVE-2023-34424 — Improper input validation in firmware (CVSS 4.4)
- Security fix: CVE-2024-21844 — Integer overflow in firmware (CVSS 4.3)
- Security fix: CVE-2023-35061 — Improper initialization (CVSS 4.3)
- Security fix: CVE-2024-26021 — Improper initialization in firmware (CVSS 2.3)
- Security fix: CVE-2023-48361 — Improper initialization in firmware (CVSS 2.3)
- Updated Intel CSME to 15.0.50.2633
- Updated Microcode to 0xBA
- Added automatic battery lifetime extender functionality
- Added BIOS option to prevent TPM PCRs changing when TBT eGPU is attached
- Added Dual Display (Panel + External Monitor) support for pre-boot (BIOS/POST)
- Fixed issue where the system cannot power on automatically when 'power on AC attach' is enabled
- Fixed missing secure boot key that prevented secure boot from being enabled
Component Versions
Section titled “ Component Versions ”This BIOS update is a bundle of updates to multiple embedded components in the system. Not all of them use the same version number.
| Component | Version | |
|---|---|---|
| EC | hx20_v0.0.1-a7cf293 | Updated |
| PD | 3.4.0.2576 | |
| Intel CSME | 15.0.50.2633 | Updated |
Windows Driver Component Versions
Section titled “ Windows Driver Component Versions ”| Driver | Version | |
|---|---|---|
| Intel Chipset | 10.1.19502.8391 | |
| Intel GNA | 3.00.00.1457 | |
| Intel Management Engine | 2336.5.29.0 | |
| Intel Serial IO | 31.100.2129.8 | |
| Intel Smart Sound | 10.29.00.9467 | |
| Intel Sensor Solution | 10.29.00.9467 | |
| Intel Display | 30.0.101.5445 | |
| Intel Dynamic Tuning | 8.7.10802.26924 | |
| Realtek Audio | 6.0.9172.1 | |
| Intel Thunderbolt | 1.41.1340.0 | |
| Intel PROSet WiFi | 23.20.0.4 | |
| Intel PROSet Bluetooth | 23.20.0.3 | |
| Goodix Fingerprint | 3.12804.0.240 | |
| Realtek Ethernet | 11013_20_07272023_08042023 | |
| SD Card Reader | v4_5_10_201 |
Installation
Section titled “Installation”Battery Extender
With the high energy density on the 61Wh battery, leaving it at 100% state of charge for an extended period of time can shorten the lifetime of the battery. If the system is left plugged into power for more than 5 days, a feature automatically limits the maximum state of charge. The timer resets after the system is disconnected from a power adapter for more than 30 minutes.
| Battery Extender Duration | Battery State of Charge |
|---|---|
| 0–5 days | 99% → 100% |
| 5–7 days | 90% → 95% |
| 7+ days | 85% → 87% |
This feature also reduces battery cycling by allowing the battery to discharge by several percent before charging again. You can also manually set a lower charge limit in BIOS to further preserve battery longevity. The feature can be enabled or disabled in the BIOS Advanced menu.
- Battery Extender — Enabled by default. Disable to always charge to 100%.
- Battery Extender Trigger — Number of days on AC before the charge limit is automatically reduced.
- Battery Extender Reset — Minutes on battery before the extender resets, causing the system to charge back to 100% on next AC connection.
Battery Charge Limit (5% Float Range)
This release modifies battery charge limit functionality to add a 5% float range, reducing microcycles when the CPU turbos. Previously the battery was held exactly at the charge limit; now it will not start charging until the battery drops 5% below the limit.
For example, with a charge limit set to 80%, the battery will maintain a state of charge between 75% and 80%, and will not charge back to 80% until it has discharged to 75% while the system is on.
If this feature is activated while the battery state of charge is above the limit, the system will discharge on battery until it reaches the upper limit.
You can check your current BIOS version following the steps here to determine if you are on the latest release.
Framework firmware is published to LVFS and updates via fwupd, which ships by default on most modern
distributions.
fwupdmgr refresh --forcefwupdmgr get-updatesfwupdmgr updateWindows
Section titled “Windows”- Download the Framework Laptop 13 11th Gen Intel® Core™ BIOS 3.22 Windows Installer.
- Run the
.exeand click "Yes" when prompted to reboot. - Wait for the firmware progress bar to complete — the system will reboot automatically. Do not interrupt.
- Download and install the Windows Driver Bundle v for your system if you are currently using a previous Driver Bundle release, or you are installing the Driver Bundle for the first time.
Secure Boot Recovery (If Needed)
If secure boot keys were lost before updating and secure boot cannot be re-enabled after the update, use the ClearVar variant instead of the standard installer to restore factory secure boot keys.
After running ClearVar and rebooting, go to Security > Secure Boot in the BIOS and set Restore Secure Boot to Factory Settings to Enabled, then save and exit.
EFI Shell Update
Section titled “ EFI Shell Update ”- Download the EFI Shell Update v3.22.
- Extract contents of zip folder to a FAT32 formatted USB drive. Cleanly unmount the drive before physically removing it, otherwise the BIOS update may not function correctly.
- Attach a charger to your device while updating.
- Boot your system while pressing F12 and boot from the thumb drive.
- Let startup.nsh run automatically.
- Follow the instructions to install the update.
Known Issues
Section titled “ Known Issues ”- The EFI update will not work with filesystems formatted using MBR
- If you get a security violation during the EFI update, disable secure boot
- This update requires a battery present to complete the update
- Linux users have reported that S3 sleep no longer works
- If the current PD version is identical to the target PD version, the EFI update process will skip the PD update, but the message displayed will be incorrect
Reporting Issues
Section titled “Reporting Issues”Please use the public issue tracker on GitHub to report issues.
If you experience an issue with the update that is related to your system firmware, please post as complete a description as you can, including relevant system information and external peripherals. Please note that we do not currently have a SLA for responding to issues on github, but we will be reviewing them through the bios release process, and will review them for future updates as well.
Please contact support if you have an issue regarding hardware, broken devices, returns, etc.