Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2025-71108: Lenovo Laptops: Incorrect Firmware Can Prevent Booting
CVE-2025-71108
Summary
Incorrect firmware on Lenovo laptops can cause booting issues. This bug has been fixed in the Linux kernel, but laptop manufacturers will also update their firmware. Affected users can update their Linux kernel to resolve the issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| linux | linux_kernel |
>= 4.13.1, < 5.10.248 >= 5.11, < 5.15.198 >= 5.16, < 6.1.160 >= 6.2, < 6.6.120 >= 6.7, < 6.12.64 >= 6.13, < 6.18.3 4.13 6.19 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
Original title
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: Handle incorrect num_connectors capability
The UCSI spec states that the num_connectors field is 7 bits, and ...
Original description
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: ucsi: Handle incorrect num_connectors capability
The UCSI spec states that the num_connectors field is 7 bits, and the
8th bit is reserved and should be set to zero.
Some buggy FW has been known to set this bit, and it can lead to a
system not booting.
Flag that the FW is not behaving correctly, and auto-fix the value
so that the system boots correctly.
Found on Lenovo P1 G8 during Linux enablement program. The FW will
be fixed, but seemed worth addressing in case it hit platforms that
aren't officially Linux supported.
usb: typec: ucsi: Handle incorrect num_connectors capability
The UCSI spec states that the num_connectors field is 7 bits, and the
8th bit is reserved and should be set to zero.
Some buggy FW has been known to set this bit, and it can lead to a
system not booting.
Flag that the FW is not behaving correctly, and auto-fix the value
so that the system boots correctly.
Found on Lenovo P1 G8 during Linux enablement program. The FW will
be fixed, but seemed worth addressing in case it hit platforms that
aren't officially Linux supported.
- https://git.kernel.org/stable/c/07c8d2a109d847775b3b4e2c3294c8e1eea75432
- https://git.kernel.org/stable/c/132fe187e0d940f388f839fe2cde9b84106ad20d
- https://git.kernel.org/stable/c/3042a57a8e8bce4a3100c3f6f03dc372aab24943
- https://git.kernel.org/stable/c/30cd2cb1abf4c4acdb1ddb468c946f68939819fb
- https://git.kernel.org/stable/c/58941bbb0050e365a98c64f1fc4a9a0ac127dba6
- https://git.kernel.org/stable/c/914605b0de8128434eafc9582445306830748b93
- https://git.kernel.org/stable/c/f72f97d0aee4a993a35f2496bca5efd24827235d
Published: 14 Jan 2026 · Updated: 15 Jun 2026 · First seen: 7 Mar 2026