CVE-2025-39701

HIGH

Linux Kernel 5.17-6.1.148, 6.2-6.6.102, 6.7-6.12.43, 6.13-6.16.3 - Firmware Update Bypass via Version Check Mismatch

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version check The security-version-number check should be used rather than the runtime version check for driver updates. Otherwise, the firmware update would fail when the update binary had a lower runtime version number than the current one. [ rjw: Changelog edits ]

Scores

CVSS v3 7.8
EPSS 0.0002
EPSS Percentile 7.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (19)
debian/debian_linux 11.0
linux/Kernel 5.17.0 - 6.1.149linux
linux/Kernel 6.13.0 - 6.16.4linux
linux/Kernel 6.2.0 - 6.6.103linux
linux/Kernel 6.7.0 - 6.12.44linux
Linux/Linux < 5.17
Linux/Linux 0db89fa243e5edc5de38c88b369e4c3755c5fb74 - 79300ff532bccbbf654992c7c0863b49a6c3973c
Linux/Linux 0db89fa243e5edc5de38c88b369e4c3755c5fb74 - 8151320c747efb22d30b035af989fed0d502176e
Linux/Linux 0db89fa243e5edc5de38c88b369e4c3755c5fb74 - 908094681f645d3a78e18ef90561a97029e2df7b
Linux/Linux 0db89fa243e5edc5de38c88b369e4c3755c5fb74 - b00219888c11519ef75d988fa8a780da68ff568e
... and 9 more
Published Sep 05, 2025
Tracked Since Feb 18, 2026