CVE-2025-38729

Advisory lineage Upstream: 0 Downstream: 58
Modified
Published: 04 Sept 2025, 15:33
Last modified:12 May 2026, 12:05

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.02% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Sept 2025, 15:33
Published
Vulnerability first disclosed
12 May 2026, 12:05
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.02% Percentile: 7%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • debiandebian_linux

    11.0

  • linuxlinux

    ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 1666207ba0a5973735ef010812536adde6174e81 | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < ebc9e06b6ea978a20abf9b87d41afc51b2d745ac | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < f03418bb9d542f44df78eec2eff4ac83c0a8ac0d | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 40714daf4d0448e1692c78563faf0ed0f9d9b5c7 | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < cd08d390d15b204cac1d3174f5f149a20c52e61a | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 29b415ec09f5b9d1dfa2423b826725a8c8796b9a | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 452ad54f432675982cc0d6eb6c40a6c86ac61dbd | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < d832ccbc301fbd9e5a1d691bdcf461cdb514595f | 4.17

  • linuxlinux_kernel

    ≥ 4.17, < 5.4.297 | ≥ 5.5, < 5.10.241 | ≥ 5.11, < 5.15.190 | ≥ 5.16, < 6.1.149 | ≥ 6.2, < 6.6.103 | ≥ 6.7, < 6.12.43 | ≥ 6.13, < 6.15.11 | ≥ 6.16, < 6.16.2 | 6.17:rc1

References (12)