In the logs I see different values for MOKvar from efi: so maybe it's calculating something wrongly (or it's just not that stable).
jak@jak-t480s:~:master$ journalctl -k | grep MOK -i Jul 12 15:14:51 jak-t480s kernel: efi: TPMFinalLog=0xbb592000 SMBIOS=0xba693000 SMBIOS 3.0=0xba690000 ACPI=0xbb5fe000 ACPI 2.0=0xbb5fe014 ESRT=0xba51d000 MEMATTR=0xb529c018 MOKvar=0xb5194000 RNG=0xba694998 TPMEventLog=0xae7e3018 jak@jak-t480s:~:master$ journalctl -k -b -2 | grep MOK Jun 27 23:10:55 jak-t480s kernel: efi: TPMFinalLog=0xbb592000 SMBIOS=0xba693000 SMBIOS 3.0=0xba690000 ACPI=0xbb5fe000 ACPI 2.0=0xbb5fe014 ESRT=0xba51d000 MEMATTR=0xb529d018 MOKvar=0xb5196000 RNG=0xba694998 TPMEventLog=0xae7e4018
In the logs I see different values for MOKvar from efi: so maybe it's calculating something wrongly (or it's just not that stable).
jak@jak- t480s:~ :master$ journalctl -k | grep MOK -i 0xbb592000 SMBIOS=0xba693000 SMBIOS 3.0=0xba690000 ACPI=0xbb5fe000 ACPI 2.0=0xbb5fe014 ESRT=0xba51d000 MEMATTR=0xb529c018 MOKvar=0xb5194000 RNG=0xba694998 TPMEventLog= 0xae7e3018 t480s:~ :master$ journalctl -k -b -2 | grep MOK 0xbb592000 SMBIOS=0xba693000 SMBIOS 3.0=0xba690000 ACPI=0xbb5fe000 ACPI 2.0=0xbb5fe014 ESRT=0xba51d000 MEMATTR=0xb529d018 MOKvar=0xb5196000 RNG=0xba694998 TPMEventLog= 0xae7e4018
Jul 12 15:14:51 jak-t480s kernel: efi: TPMFinalLog=
jak@jak-
Jun 27 23:10:55 jak-t480s kernel: efi: TPMFinalLog=