CVE-2025-39701
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39701 was disclosed on September 5, 2025, affecting the Linux kernel. The vulnerability is related to the ACPI pfr_update driver's version check functionality. The issue involves an incorrect implementation where the runtime version check was being used instead of the security-version-number check for driver updates (NVD).

Technical details

The vulnerability exists in the ACPI pfr_update driver where the version checking mechanism was improperly implemented. Specifically, the driver was using runtime version checks instead of security-version-number checks when processing driver updates. This incorrect implementation could cause firmware updates to fail when the update binary had a lower runtime version number than the current one, even if the security version was appropriate (NVD).

Impact

The vulnerability could cause firmware updates to fail when the update binary has a lower runtime version number than the current one, potentially preventing important security updates from being applied. This could leave systems vulnerable to security issues that would otherwise be addressed by the firmware update (NVD).

Mitigation and workarounds

The issue has been resolved in the Linux kernel through a patch that corrects the version checking mechanism. The fix implements the proper security-version-number check instead of the runtime version check for driver updates (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-devel
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • bpftool
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-trace
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-headers
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management