I
n the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 power domain descriptors, too UAC3 power domain descriptors need to be verified with its variable bLength for avoiding the unexpected OOB accesses by malicious firmware, too.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
08 Jan 2026, 17:31
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CWE | CWE-787 | |
| First Time |
Debian
Linux linux Kernel Linux Debian debian Linux |
|
| References | () https://git.kernel.org/stable/c/07c8d78dbb5e0ff8b23f7fd69cd1d4e2ba22b3dc - Patch | |
| References | () https://git.kernel.org/stable/c/1666207ba0a5973735ef010812536adde6174e81 - Patch | |
| References | () https://git.kernel.org/stable/c/29b415ec09f5b9d1dfa2423b826725a8c8796b9a - Patch | |
| References | () https://git.kernel.org/stable/c/40714daf4d0448e1692c78563faf0ed0f9d9b5c7 - Patch | |
| References | () https://git.kernel.org/stable/c/452ad54f432675982cc0d6eb6c40a6c86ac61dbd - Patch | |
| References | () https://git.kernel.org/stable/c/cd08d390d15b204cac1d3174f5f149a20c52e61a - Patch | |
| References | () https://git.kernel.org/stable/c/d832ccbc301fbd9e5a1d691bdcf461cdb514595f - Patch | |
| References | () https://git.kernel.org/stable/c/ebc9e06b6ea978a20abf9b87d41afc51b2d745ac - Patch | |
| References | () https://git.kernel.org/stable/c/f03418bb9d542f44df78eec2eff4ac83c0a8ac0d - Patch | |
| References | () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html - Third Party Advisory, Mailing List | |
| References | () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory, Mailing List | |
| CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:* |
03 Nov 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
05 Sep 2025, 17:47
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-04 16:15
Updated : 2026-01-08 17:31
NVD link : CVE-2025-38729
Mitre link : CVE-2025-38729
CVE.ORG link : CVE-2025-38729
JSON object : View
Products Affected
CWE
CWE-787
Out-of-bounds Write