CVE-2025-39701: ACPI: pfr_update: Fix the driver update version check
In the Linux kernel, the following vulnerability has been resolved:
ACPI: pfrupdate: Fix the driver update version check
The security-version-number check should be used rather than the runtime version check for driver updates.
Otherwise, the firmware update would fail when the update binary had a lower runtime version number than the current one.
[ rjw: Changelog edits ]
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39701?
CVE-2025-39701 has not been assigned a severity rating yet.
How do I fix CVE-2025-39701?
To fix CVE-2025-39701, update to the latest version of the Linux kernel that includes the patch addressing this vulnerability.
What specific component does CVE-2025-39701 affect?
CVE-2025-39701 affects the ACPI subsystem in the Linux kernel.
Can CVE-2025-39701 lead to a system compromise?
CVE-2025-39701 does not directly indicate a system compromise, but it involves firmware updates that could be critical for security.
Is there a workaround for CVE-2025-39701 until a patch is applied?
There are no known workarounds for CVE-2025-39701; updating the kernel is recommended for resolution.