PSA: You now need the recently-released fwupd 2.0.12 to deploy the latest dbx and KEK updates.
It's not what I wanted to do, but Microsoft actually found some cases where out-of-efivar-space lead to the machine being bricked, rather than just the write failing. It's not something I've seen in Linux but it's the same mechanism.
As fwupd 2.0.12 is the first release that enforces those free space checks, out of an abundance of caution I've raised the fwupd dep on the two most recent dbx files.