CVE-2025-38729
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.02%• Percentile: 7%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- debian•debian_linux
11.0
- linux•linux
≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 1666207ba0a5973735ef010812536adde6174e81 | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < ebc9e06b6ea978a20abf9b87d41afc51b2d745ac | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < f03418bb9d542f44df78eec2eff4ac83c0a8ac0d | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 40714daf4d0448e1692c78563faf0ed0f9d9b5c7 | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < cd08d390d15b204cac1d3174f5f149a20c52e61a | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 29b415ec09f5b9d1dfa2423b826725a8c8796b9a | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < 452ad54f432675982cc0d6eb6c40a6c86ac61dbd | ≥ 9a2fe9b801f585baccf8352d82839dcd54b300cf, < d832ccbc301fbd9e5a1d691bdcf461cdb514595f | 4.17
- linux•linux_kernel
≥ 4.17, < 5.4.297 | ≥ 5.5, < 5.10.241 | ≥ 5.11, < 5.15.190 | ≥ 5.16, < 6.1.149 | ≥ 6.2, < 6.6.103 | ≥ 6.7, < 6.12.43 | ≥ 6.13, < 6.15.11 | ≥ 6.16, < 6.16.2 | 6.17:rc1
References (12)
- https://git.kernel.org/stable/c/1666207ba0a5973735ef010812536adde6174e81
- https://git.kernel.org/stable/c/ebc9e06b6ea978a20abf9b87d41afc51b2d745ac
- https://git.kernel.org/stable/c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0d
- https://git.kernel.org/stable/c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7
- https://git.kernel.org/stable/c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc
- https://git.kernel.org/stable/c/cd08d390d15b204cac1d3174f5f149a20c52e61a
- https://git.kernel.org/stable/c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a
- https://git.kernel.org/stable/c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd
- https://git.kernel.org/stable/c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html