cbcvebase.
CVE-2025-38729
published 2025-09-04

CVE-2025-38729: In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < 1666207ba0a5973735ef010812536adde6174e811666207ba0a5973735ef010812536adde6174e81
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < ebc9e06b6ea978a20abf9b87d41afc51b2d745acebc9e06b6ea978a20abf9b87d41afc51b2d745ac
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < f03418bb9d542f44df78eec2eff4ac83c0a8ac0df03418bb9d542f44df78eec2eff4ac83c0a8ac0d
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < 40714daf4d0448e1692c78563faf0ed0f9d9b5c740714daf4d0448e1692c78563faf0ed0f9d9b5c7
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < 07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < cd08d390d15b204cac1d3174f5f149a20c52e61acd08d390d15b204cac1d3174f5f149a20c52e61a
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < 29b415ec09f5b9d1dfa2423b826725a8c8796b9a29b415ec09f5b9d1dfa2423b826725a8c8796b9a
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < 452ad54f432675982cc0d6eb6c40a6c86ac61dbd452ad54f432675982cc0d6eb6c40a6c86ac61dbd
linuxlinux>= 9a2fe9b801f585baccf8352d82839dcd54b300cf < d832ccbc301fbd9e5a1d691bdcf461cdb514595fd832ccbc301fbd9e5a1d691bdcf461cdb514595f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.43-16.12.43-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 5.15.0-163.1735.15.0-163.173
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 4.17 < 5.4.2975.4.297
linuxlinux_kernel>= 5.11 < 5.15.1905.15.190
linuxlinux_kernel>= 5.16 < 6.1.1496.1.149
linuxlinux_kernel>= 5.5 < 5.10.2415.10.241
linuxlinux_kernel>= 6.13 < 6.15.116.15.11

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH