Junglewise Threat Intelligence

CVE-2025-39701: Linux Kernel ACPI incorrect version check in pfr_update

CVE-2025-39701 · Severity: high · CVSS 7.8 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's ACPI Platform Firmware Runtime Update (PFRU) driver could allow a local user to interfere with firmware update processes. The driver incorrectly checked runtime version numbers instead of security version numbers, which could cause legitimate updates to fail or potentially allow for improper firmware states. This affects systems using specific ACPI-based firmware update mechanisms, potentially impacting system stability and security integrity.

Technical details

A vulnerability exists in the Linux kernel's ACPI Platform Firmware Runtime Update (PFRU) driver (drivers/acpi/pfr_update.c). The 'applicable_image' function incorrectly validated driver updates by comparing the runtime version (rt_ver) against the capability's runtime version (drv_rt_version) instead of using the Security Version Number (SVN). This logic error could cause firmware updates to fail if the update binary has a lower runtime version than the current one, even if the security version is valid. A local attacker with low privileges could potentially exploit this logic flaw to impact the integrity or availability of the firmware update process. Patches have been released across multiple stable kernel branches to ensure the 'svn_ver' is used for these checks.

Affected products

  • Linux Linux Kernel 5.17 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-09-05: disclosed: Initial publication of the vulnerability details.
  • 2025-08-28: patched: Fixes committed to various stable kernel branches.

References