Home

Description

In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version check The security-version-number check should be used rather than the runtime version check for driver updates. Otherwise, the firmware update would fail when the update binary had a lower runtime version number than the current one. [ rjw: Changelog edits ]

PUBLISHED Reserved 2025-04-16 | Published 2025-09-05 | Updated 2026-05-12 | Assigner Linux

Product status

Default status
unaffected

0db89fa243e5edc5de38c88b369e4c3755c5fb74 (git) before 79300ff532bccbbf654992c7c0863b49a6c3973c
affected

0db89fa243e5edc5de38c88b369e4c3755c5fb74 (git) before cf0a88124e357bffda487cbf3cb612bb97eb97e4
affected

0db89fa243e5edc5de38c88b369e4c3755c5fb74 (git) before b00219888c11519ef75d988fa8a780da68ff568e
affected

0db89fa243e5edc5de38c88b369e4c3755c5fb74 (git) before 908094681f645d3a78e18ef90561a97029e2df7b
affected

0db89fa243e5edc5de38c88b369e4c3755c5fb74 (git) before 8151320c747efb22d30b035af989fed0d502176e
affected

Default status
affected

5.17
affected

Any version before 5.17
unaffected

6.1.149 (semver)
unaffected

6.6.103 (semver)
unaffected

6.12.44 (semver)
unaffected

6.16.4 (semver)
unaffected

6.17 (original_commit_for_fix)
unaffected

References

lists.debian.org/debian-lts-announce/2025/10/msg00008.html

cert-portal.siemens.com/productcert/html/ssa-032379.html

git.kernel.org/...c/79300ff532bccbbf654992c7c0863b49a6c3973c

git.kernel.org/...c/cf0a88124e357bffda487cbf3cb612bb97eb97e4

git.kernel.org/...c/b00219888c11519ef75d988fa8a780da68ff568e

git.kernel.org/...c/908094681f645d3a78e18ef90561a97029e2df7b

git.kernel.org/...c/8151320c747efb22d30b035af989fed0d502176e

cve.org (CVE-2025-39701)

nvd.nist.gov (CVE-2025-39701)

Download JSON