Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

CVE-2025-39701: Linux Kernel: Firmware Updates Fail if Newer Version Installed

CVE-2025-39701
Summary

A fix has been made to the Linux kernel to prevent firmware updates from failing when a newer version is installed. This affects systems that use the ACPI driver for firmware updates. Users should update their Linux kernel to ensure firmware updates can proceed correctly.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
linux linux_kernel >= 5.17, < 6.1.149
>= 6.2, < 6.6.103
>= 6.7, < 6.12.44
>= 6.13, < 6.16.4
6.17
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
debian debian_linux 11.0
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Original title
In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: Fix the driver update version check The security-version-number check should be used rather than the runtime ...
Original description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: pfr_update: Fix the driver update version check

The security-version-number check should be used rather
than the runtime version check for driver updates.

Otherwise, the firmware update would fail when the update binary had
a lower runtime version number than the current one.

[ rjw: Changelog edits ]
nvd CVSS3.1 7.8
Published: 5 Sep 2025 · Updated: 15 Jun 2026 · First seen: 7 Mar 2026