CVE-2025-39701
HIGHLinux Kernel 5.17-6.1.148, 6.2-6.6.102, 6.7-6.12.43, 6.13-6.16.3 - Firmware Update Bypass via Version Check Mismatch
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version check The security-version-number check should be used rather than the runtime version check for driver updates. Otherwise, the firmware update would fail when the update binary had a lower runtime version number than the current one. [ rjw: Changelog edits ]
References (7)
Core 7
Core References
Third Party Advisory, Mailing List
https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
Vendor Advisory
https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Scores
CVSS v3
7.8
EPSS
0.0002
EPSS Percentile
7.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (19)
debian/debian_linux
11.0
linux/Kernel
5.17.0 - 6.1.149linux
linux/Kernel
6.13.0 - 6.16.4linux
linux/Kernel
6.2.0 - 6.6.103linux
linux/Kernel
6.7.0 - 6.12.44linux
Linux/Linux
< 5.17
Linux/Linux
0db89fa243e5edc5de38c88b369e4c3755c5fb74 - 79300ff532bccbbf654992c7c0863b49a6c3973c
Linux/Linux
0db89fa243e5edc5de38c88b369e4c3755c5fb74 - 8151320c747efb22d30b035af989fed0d502176e
Linux/Linux
0db89fa243e5edc5de38c88b369e4c3755c5fb74 - 908094681f645d3a78e18ef90561a97029e2df7b
Linux/Linux
0db89fa243e5edc5de38c88b369e4c3755c5fb74 - b00219888c11519ef75d988fa8a780da68ff568e
... and 9 more
Published
Sep 05, 2025
Tracked Since
Feb 18, 2026